CVE-2026-34614: Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79)
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34614?
CVE-2026-34614 is considered a moderate-severity vulnerability due to the potential for reflected cross-site scripting attacks.
How do I fix CVE-2026-34614?
To fix CVE-2026-34614, update Adobe Connect to version 2025.4 or later where the vulnerability has been addressed.
What software is affected by CVE-2026-34614?
CVEs 2025.3 and earlier versions of Adobe Connect are affected by CVE-2026-34614.
What type of vulnerability is CVE-2026-34614?
CVE-2026-34614 is a reflected Cross-Site Scripting (XSS) vulnerability.
How can an attacker exploit CVE-2026-34614?
An attacker can exploit CVE-2026-34614 by convincing a victim to visit a malicious URL referencing a vulnerable Adobe Connect page.