Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4505 articles · 223849 vulns · 37/41 feeds (7d)
← Back to list
9.3
CVE-2026-75698PATCHED
adobe · adobe connect

Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79)

Description

Adobe Connect is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.

Affected Products

VendorProductVersions
adobeadobe connect0, 0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
adobeconnectcert_advisory90%

References

  • https://helpx.adobe.com/security/products/connect/apsb26-150.html(vendor-advisory)

Related News (3 articles)

Tier D
SecurityWeek4d ago
Adobe Patches Critical Flaws in Connect, AEM Forms
→ No new info (linked only)
Tier B
BSI Advisories4d ago
[NEU] [hoch] Adobe Connect: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB5d ago
CVE-2026-75698 | Adobe Connect/Connect Android Mobile App cross site scripting
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.3 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
12.11.112.124.5
CWECWE-79
PublishedSep 22, 2026
Trending Score29
Source articles3
Independent3
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-71362EXPKEV
Adobe Commerce | Incorrect Authorization (CWE-863)
Trending: 109
CRITICALCVE-2026-75745
Adobe Experience Manager Forms JEE | Incorrect Authorization (CWE-863)
Trending: 36
CRITICALCVE-2026-75682
Adobe Connect | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Trending: 29
CRITICALCVE-2026-82000
Adobe Experience Manager Forms JEE | Server-Side Request Forgery (SSRF) (CWE-918)
Trending: 29
HIGHCVE-2026-34689
Adobe Connect | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Trending: 28

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 22, 2026
Discovered by ZDM
Sep 22, 2026
Patch Available
Sep 23, 2026