Connect
Vendor:
First CVE: Jun 13, 2015 · Active for 11 years
74
Total CVEs
More Total CVEs than 99% of tracked products
6.7
Avg CVEs / Year
Higher CVE frequency than 92% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Connect over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 13, 2015
11 years ago
Most Recent CVE
Apr 14, 2026
101 days ago
CVE Severity & Scoring
Connect74 CVEs
62%
14%
24%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (2.7%)
Network70 (94.6%)
Unknown2 (2.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low72 (97.3%)
High0 (0.0%)
Unknown2 (2.7%)
User Interaction
None20 (27.0%)
Unknown2 (2.7%)
Required52 (70.3%)
Privileges Required
Low10 (13.5%)
High2 (2.7%)
None60 (81.1%)
Unknown2 (2.7%)
Top CVEs
Signals from CVEs in this product scope (74 CVEs).
74 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-22232MEDIUM Adobe Connect versions 11.4.5 (and earlier), 12.1.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attack | Feb 17, 2023 | 5.3 | 79 | NO | YES |
CVE-2016-7851MEDIUM Adobe Connect version 9.5.6 and earlier does not adequately validate input in the events registration module. This vulnerability could be exploited in cross-site scripting attacks. | Nov 8, 2016 | 6.1 | 35 | NO | YES |
CVE-2018-12804CRITICAL Adobe Connect versions 9.7.5 and earlier have an Authentication Bypass vulnerability. Successful exploitation could lead to session hijacking. | Jul 20, 2018 | 9.8 | 34 | NO | NO |
CVE-2026-27303CRITICAL Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of t | Apr 14, 2026 | 9.6 | 33 | NO | NO |
CVE-2026-34615CRITICAL Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of t | Apr 14, 2026 | 9.3 | 32 | NO | NO |
CVE-2025-49553CRITICAL Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute malicious scripts in | Oct 14, 2025 | 9.3 | 32 | NO | NO |
CVE-2018-12805CRITICAL Adobe Connect versions 9.7.5 and earlier have an Insecure Library Loading vulnerability. Successful exploitation could lead to privilege escalation. | Jul 20, 2018 | 9.8 | 32 | NO | NO |
CVE-2026-27246CRITICAL Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malici | Apr 14, 2026 | 9.3 | 31 | NO | NO |
CVE-2026-27245CRITICAL Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malici | Apr 14, 2026 | 9.3 | 31 | NO | NO |
CVE-2021-40719CRITICAL Adobe Connect version 11.2.3 (and earlier) is affected by a Deserialization of Untrusted Data vulnerability to achieve arbitrary method invocation when AMF messages are deserialize | Oct 21, 2021 | 9.8 | 31 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (74 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
1.4% of CVEs· 96th percentile
ExploitDB
2 CVEs
2.7% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (74 CVEs).
Media Mentions
Signals from CVEs in this product scope (74 CVEs).
Top CNAs Publishing CVEs For Connect
Top CWEs
Versions
No cataloged versions.