Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-27303

33
FAUCET Score

CVE-2026-27303 is a deserialization vulnerability affecting Adobe Connect versions 2025.3, 12.10, and earlier that permits arbitrary code execution within the current user's context without requiring user interaction. The flaw stems from improper handling of untrusted data during the deserialization process, creating a critical security gap in this widely-used conferencing platform. The vulnerability carries a CVSS score of 9.6 (Critical) with a network-based attack vector requiring no authentication or special privileges, though exploitation does require user interaction despite initial assessments suggesting otherwise. The attack has high impact potential across confidentiality, integrity, and availability, with scope changes indicating the ability to affect systems beyond the vulnerable component itself. Exploitation status remains limited at present, with the vulnerability absent from active exploitation databases and showing no evidence of available exploit code or widespread weaponization. The EPSS score of 0.037 indicates relatively lower probability of exploitation compared to other published vulnerabilities, and the threat has not yet been added to known exploited vulnerability catalogs, suggesting active monitoring is appropriate but immediate emergency response may not be warranted for all organizations.

Impacted Technologies

VendorProductVersion(s)CPE
< 12.11CPE matchmatch criteria
cpe:2.3:a:adobe:connect:*:*:*:*:*:-:*:*
<= 2025.3CPE matchmatch criteria
cpe:2.3:a:adobe:connect_desktop_application:*:*:*:*:*:macos:*:*
< 2025.9.15CPE matchmatch criteria
cpe:2.3:a:adobe:connect_desktop_application:*:*:*:*:*:windows:*:*

CVSS Data

CVSS version used by this source: 3.1

9.6CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.61%
Probability of exploitation in next 30 days
EPSS Percentile
45.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0061 is in the 26th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

adobevendor investigatingvia nvd_reference
View patch

References

helpx.adobe.com / security/products/connect/apsb26-37.html
Vendor Advisory