CVE-2026-34614 is a reflected Cross-Site Scripting vulnerability affecting Adobe Connect versions 2025.3, 12.10 and earlier. The flaw allows attackers to execute malicious JavaScript within a victim's browser if they can be tricked into visiting a specially crafted URL. The vulnerability has expanded scope, potentially affecting additional system components beyond the initially targeted area. The vulnerability carries a CVSS score of 6.1 (Medium severity) with a network-based attack vector requiring no special privileges, though user interaction is necessary to trigger the payload. The attack has low complexity and results in limited confidentiality and integrity impacts with no availability impact. The FAUCET Risk Score of 43.0/100 indicates moderate concern within the broader vulnerability landscape. There is currently no evidence of active exploitation, and the vulnerability does not appear on the CISA Known Exploited Vulnerabilities list. The EPSS score of 0.000780000 suggests low probability of exploitation, and the vulnerability remains on the Inactive Hot List. However, organizations should still prioritize patching as reflected XSS vulnerabilities typically have readily available exploit proof-of-concepts once public details emerge.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12.11CPE matchmatch criteria | cpe:2.3:a:adobe:connect:*:*:*:*:*:-:*:* | ||
<= 2025.3CPE matchmatch criteria | cpe:2.3:a:adobe:connect_desktop_application:*:*:*:*:*:macos:*:* | ||
< 2025.9.15CPE matchmatch criteria | cpe:2.3:a:adobe:connect_desktop_application:*:*:*:*:*:windows:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.