Description
Adobe Connect is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
Published: 2026-09-22
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Arbitrary code execution
Action: Immediate Patch
AI Analysis

Impact

Adobe Connect suffers from an Improper Input Validation flaw that can let an attacker run arbitrary code in the context of the user who accesses a crafted page. The vulnerability is triggered when a victim opens a maliciously constructed URL or interacts with a compromised web page, and the bug causes the scope to be altered, potentially allowing the attacker to gain privileges beyond the original user session.

Affected Systems

The flaw affects Adobe Connect desktop and the Adobe Connect Android Mobile App. No specific version numbers are provided, so all currently deployed installations without the latest patch are considered at risk.

Risk and Exploitability

With a CVSS base score of 9.3, the risk level is high. The EPSS score is unavailable, but the vulnerability is not yet listed in the CISA KEV catalog, indicating limited known exploitation. Exploitation requires user interaction, so the likelihood is reduced compared to automated attacks, but the impact—arbitrary code execution—remains severe if an adversary succeeds. The potential social engineering component underscores the need for user awareness and prompt patching.

Generated by OpenCVE AI on September 22, 2026 at 21:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe Connect update that closes the input validation flaw
  • Configure network firewall or web filtering to block requests containing known malicious patterns for this vulnerability
  • Educate users to recognize and avoid suspicious URLs that could trigger the flaw

Generated by OpenCVE AI on September 22, 2026 at 21:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description Adobe Connect is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
Title Adobe Connect | Improper Input Validation (CWE-20)
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-22T19:10:21.327Z

Reserved: 2026-08-18T01:29:54.617Z

Link: CVE-2026-75686

cve-icon Vulnrichment

Updated: 2026-09-22T19:10:18.841Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-22T19:16:46.520

Modified: 2026-09-22T20:17:05.960

Link: CVE-2026-75686

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T21:15:07Z

Weaknesses
  • CWE-20

    Improper Input Validation