Junglewise Threat Intelligence

CVE-2026-75684: Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scrip

CVE-2026-75684 · Severity: critical · CVSS 9.3 · Published 2026-09-22

Executive brief

Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.

Affected products

  • Apple macOS
  • Microsoft Windows
  • Adobe connect_for_mobile

References

Related threats