CVE-2026-27246 is a DOM-based Cross-Site Scripting (XSS) vulnerability affecting Adobe Connect versions 2025.3, 12.10 and earlier, which allows attackers to execute malicious JavaScript in a victim's browser by manipulating the DOM environment. The vulnerability carries a CVSS score of 9.3 (Critical) with a network-based attack vector requiring no privileges and relatively low complexity, though user interaction is necessary to exploit it. The attack has a changed scope and could result in high confidentiality and integrity impacts. Currently, there is no evidence of active exploitation in the wild, no publicly available exploit code is documented, and community attention remains low as indicated by the vulnerability's absence from the Known Exploited Vulnerabilities catalog and its inactive status on security hotlists. Organizations running the affected Adobe Connect versions should prioritize patching, as the network-accessible nature and critical severity rating warrant prompt remediation despite the current lack of exploitation activity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12.11CPE matchmatch criteria | cpe:2.3:a:adobe:connect:*:*:*:*:*:-:*:* | ||
<= 2025.3CPE matchmatch criteria | cpe:2.3:a:adobe:connect_desktop_application:*:*:*:*:*:macos:*:* | ||
< 2025.9.15CPE matchmatch criteria | cpe:2.3:a:adobe:connect_desktop_application:*:*:*:*:*:windows:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.