Executive brief
Adobe Connect, a web conferencing platform used for online meetings and webinars, is affected by a critical security flaw. An attacker can exploit this by tricking a user into visiting a malicious link or a compromised website. If successful, the attacker could gain the ability to run unauthorized commands and take control of the user's computer, potentially leading to data theft or full system compromise.
Technical details
A deserialization of untrusted data vulnerability (CWE-502) exists in Adobe Connect versions 2025.9.15, 2025.8.157 and earlier. The flaw occurs when the application processes maliciously crafted serialized data without sufficient validation. An unauthenticated remote attacker can exploit this by inducing a user to interact with a malicious URL or compromised web page. Successful exploitation allows for arbitrary code execution in the context of the current user. The vulnerability has a high impact on confidentiality, integrity, and availability, and notably involves a change in scope (CVSS:3.1/S:C).
Affected products
- Adobe Connect 2025.9.15, 2025.8.157 and earlier
Timeline
- 2026-05-12: advisory: Initial advisory published by Adobe
- 2026-05-12: disclosed