CVE-2026-27303 is a deserialization vulnerability affecting Adobe Connect versions 2025.3, 12.10, and earlier that permits arbitrary code execution within the current user's context without requiring user interaction. The flaw stems from improper handling of untrusted data during the deserialization process, creating a critical security gap in this widely-used conferencing platform. The vulnerability carries a CVSS score of 9.6 (Critical) with a network-based attack vector requiring no authentication or special privileges, though exploitation does require user interaction despite initial assessments suggesting otherwise. The attack has high impact potential across confidentiality, integrity, and availability, with scope changes indicating the ability to affect systems beyond the vulnerable component itself. Exploitation status remains limited at present, with the vulnerability absent from active exploitation databases and showing no evidence of available exploit code or widespread weaponization. The EPSS score of 0.037 indicates relatively lower probability of exploitation compared to other published vulnerabilities, and the threat has not yet been added to known exploited vulnerability catalogs, suggesting active monitoring is appropriate but immediate emergency response may not be warranted for all organizations.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12.11CPE matchmatch criteria | cpe:2.3:a:adobe:connect:*:*:*:*:*:-:*:* | ||
<= 2025.3CPE matchmatch criteria | cpe:2.3:a:adobe:connect_desktop_application:*:*:*:*:*:macos:*:* | ||
< 2025.9.15CPE matchmatch criteria | cpe:2.3:a:adobe:connect_desktop_application:*:*:*:*:*:windows:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.