CVE-2026-34615 is a critical deserialization vulnerability affecting Adobe Connect versions 2025.3, 12.10 and earlier that allows unauthenticated attackers to execute arbitrary code in the context of the current user without requiring any user interaction. The vulnerability stems from improper handling of untrusted data during the deserialization process. The vulnerability carries a CVSS score of 9.3 (Critical) with a network-based attack vector, low attack complexity, and no authentication requirements. While user interaction is marked in the CVSS scoring, exploitation can achieve high confidentiality and integrity impacts, with scope changes that affect resources beyond the vulnerable component itself. There is no evidence of active exploitation at this time, as the vulnerability is not listed in the Known Exploited Vulnerabilities (KEV) catalog and is classified as Inactive on the Hot List. The EPSS score of 0.036 indicates relatively low probability of exploitation in the wild, though the moderate FAUCET Risk Score of 57.0 suggests organizations should prioritize patching given the severity rating and potential for impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12.11CPE matchmatch criteria | cpe:2.3:a:adobe:connect:*:*:*:*:*:-:*:* | ||
<= 2025.3CPE matchmatch criteria | cpe:2.3:a:adobe:connect_desktop_application:*:*:*:*:*:macos:*:* | ||
< 2025.9.15CPE matchmatch criteria | cpe:2.3:a:adobe:connect_desktop_application:*:*:*:*:*:windows:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.