Adobe has disclosed a critical reflected cross-site scripting flaw in Adobe Connect that carries a CVSS 3.1 base score of 9.3 and, according to Adobe's advisory, could potentially give an attacker elevated access to a victim's account or session.
What Is It
CVE-2026-75698 is a reflected cross-site scripting vulnerability (CWE-79) in Adobe Connect. An attacker can inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation requires user interaction; the victim must visit a maliciously crafted URL or interact with a compromised web page.
The issue was published by Adobe PSIRT on 2026-09-22 and is currently listed in NVD as "Awaiting Analysis," so the severity characterization below reflects Adobe's own scoring rather than an independent assessment.
Why It Matters
The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N, network attack vector, low complexity, no privileges required, and a changed scope, which is what pushes a reflected XSS bug into critical territory at 9.3. Confidentiality and integrity impacts are both rated HIGH; availability is unaffected.
The practical read: if the scoring holds up under analysis, an unauthenticated attacker would need only to get a target to click a link. Because scope is rated as changed, the impact would not be confined to the vulnerable component. Adobe Connect is a web conferencing and virtual classroom platform, so session takeover of meeting hosts and administrators is the scenario worth planning against; though no public exploit or proof of concept has been reported.
What's Vulnerable
Per Adobe's affected-product data:
- Adobe Connect: versions 12.11 and earlier are affected. Versions 12.11.1 and 12.12 are unaffected.
- Adobe Connect Android Mobile App: versions 4.4 and earlier are affected. Version 4.5 is unaffected.
All other versions default to unaffected status.
Patch Status
Fixed builds are available. Upgrade Adobe Connect to 12.11.1 or 12.12, and the Adobe Connect Android Mobile App to 4.5. Full details are in Adobe security bulletin APSB26-150.
CVE-2026-75698 is not listed in the CISA Known Exploited Vulnerabilities catalog: there is no confirmation of active exploitation, and no federally mandated remediation deadline at this time. Prioritize on the CVSS rating and your own exposure rather than on KEV status.
Sources
- NVD, CVE-2026-75698: https://nvd.nist.gov/vuln/detail/CVE-2026-75698
- Adobe Security Bulletin APSB26-150: https://helpx.adobe.com/security/products/connect/apsb26-150.html
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog