Junglewise Threat Intelligence

CVE-2026-75682: Adobe Connect SQL injection leading to arbitrary code execution

CVE-2026-75682 · Severity: critical · CVSS 9.9 · Published 2026-09-22

Technologies: Apple macOS, Microsoft Windows, Adobe Connect For Mobile. Vendors: Apple, Microsoft, Adobe.

Executive brief

Adobe Connect, a web conferencing and collaboration platform, contains a SQL injection vulnerability that could allow a low-privileged attacker to execute arbitrary code within the application. An attacker could exploit this flaw without user interaction to gain elevated access, take over accounts, or compromise the confidentiality and integrity of user data and sessions.

Technical details

A SQL injection flaw in Adobe Connect allows improper neutralization of special characters in SQL commands. A low-privileged attacker can craft malicious SQL queries that execute arbitrary SQL commands against the backend database, potentially leading to arbitrary code execution in the context of the application. No user interaction is required to exploit this vulnerability.

Affected products

  • Adobe Connect

Timeline

  • 2026-09-22: disclosed

References

Related threats