Vulnerability Details CVE-2026-27245
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Scope is changed.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 28.6%
CVSS Severity
CVSS v3 Score 9.3
Products affected by CVE-2026-27245
-
cpe:2.3:a:adobe:connect:-
-
cpe:2.3:a:adobe:connect:1.0.0.1
-
cpe:2.3:a:adobe:connect:10
-
cpe:2.3:a:adobe:connect:10.1
-
cpe:2.3:a:adobe:connect:10.2
-
cpe:2.3:a:adobe:connect:10.5
-
cpe:2.3:a:adobe:connect:10.6
-
cpe:2.3:a:adobe:connect:10.6.1
-
cpe:2.3:a:adobe:connect:10.6.2
-
cpe:2.3:a:adobe:connect:10.8
-
cpe:2.3:a:adobe:connect:11.0
-
cpe:2.3:a:adobe:connect:11.0.5
-
cpe:2.3:a:adobe:connect:11.0.6
-
cpe:2.3:a:adobe:connect:11.0.7
-
cpe:2.3:a:adobe:connect:11.2
-
cpe:2.3:a:adobe:connect:11.2.1
-
cpe:2.3:a:adobe:connect:11.2.2
-
cpe:2.3:a:adobe:connect:11.4.9
-
cpe:2.3:a:adobe:connect:12.0
-
cpe:2.3:a:adobe:connect:12.1
-
cpe:2.3:a:adobe:connect:12.1.5
-
cpe:2.3:a:adobe:connect:12.10
-
cpe:2.3:a:adobe:connect:12.2
-
cpe:2.3:a:adobe:connect:12.3
-
cpe:2.3:a:adobe:connect:12.4
-
cpe:2.3:a:adobe:connect:12.4.1
-
cpe:2.3:a:adobe:connect:12.5
-
cpe:2.3:a:adobe:connect:12.5.1
-
cpe:2.3:a:adobe:connect:12.6
-
cpe:2.3:a:adobe:connect:12.6.1
-
cpe:2.3:a:adobe:connect:12.7
-
cpe:2.3:a:adobe:connect:12.8
-
cpe:2.3:a:adobe:connect:12.9
-
cpe:2.3:a:adobe:connect:6.0
-
cpe:2.3:a:adobe:connect:6.1
-
cpe:2.3:a:adobe:connect:6.2
-
cpe:2.3:a:adobe:connect:6.3
-
cpe:2.3:a:adobe:connect:7.0
-
cpe:2.3:a:adobe:connect:7.2
-
cpe:2.3:a:adobe:connect:7.3
-
cpe:2.3:a:adobe:connect:7.5
-
cpe:2.3:a:adobe:connect:8.0
-
cpe:2.3:a:adobe:connect:8.1
-
cpe:2.3:a:adobe:connect:8.2
-
cpe:2.3:a:adobe:connect:8.2.1
-
cpe:2.3:a:adobe:connect:8.2.2
-
cpe:2.3:a:adobe:connect:9.0
-
cpe:2.3:a:adobe:connect:9.0.2
-
cpe:2.3:a:adobe:connect:9.0.3
-
cpe:2.3:a:adobe:connect:9.1
-
cpe:2.3:a:adobe:connect:9.1.2
-
cpe:2.3:a:adobe:connect:9.2
-
cpe:2.3:a:adobe:connect:9.3
-
cpe:2.3:a:adobe:connect:9.4.1
-
cpe:2.3:a:adobe:connect:9.4.2
-
cpe:2.3:a:adobe:connect:9.5
-
cpe:2.3:a:adobe:connect:9.5.2
-
cpe:2.3:a:adobe:connect:9.5.3
-
cpe:2.3:a:adobe:connect:9.5.4
-
cpe:2.3:a:adobe:connect:9.5.5
-
cpe:2.3:a:adobe:connect:9.5.6
-
cpe:2.3:a:adobe:connect:9.5.7
-
cpe:2.3:a:adobe:connect:9.6
-
cpe:2.3:a:adobe:connect:9.6.1
-
cpe:2.3:a:adobe:connect:9.6.2
-
cpe:2.3:a:adobe:connect:9.7
-
cpe:2.3:a:adobe:connect:9.7.5
-
cpe:2.3:a:adobe:connect:9.8
-
cpe:2.3:a:adobe:connect:9.8.1
-
cpe:2.3:a:adobe:connect_desktop_application:*
-
cpe:2.3:a:adobe:connect_desktop_application:2021.11.22.64
-
cpe:2.3:a:adobe:connect_desktop_application:2021.3.27
-
cpe:2.3:a:adobe:connect_desktop_application:2021.3.4
-
cpe:2.3:a:adobe:connect_desktop_application:2021.4.36.64
-
cpe:2.3:a:adobe:connect_desktop_application:2021.6.27.32
-
cpe:2.3:a:adobe:connect_desktop_application:2021.6.27.64
-
cpe:2.3:a:adobe:connect_desktop_application:2021.9.28.64
-
cpe:2.3:a:adobe:connect_desktop_application:2022.5.109
-
cpe:2.3:a:adobe:connect_desktop_application:2022.7.183
-
cpe:2.3:a:adobe:connect_desktop_application:2023.5.308
-
cpe:2.3:a:adobe:connect_desktop_application:2023.6.382
-
cpe:2.3:a:adobe:connect_desktop_application:2023.9.482
-
cpe:2.3:a:adobe:connect_desktop_application:2024.11
-
cpe:2.3:a:adobe:connect_desktop_application:2024.4.729
-
cpe:2.3:a:adobe:connect_desktop_application:2024.6.22
-
cpe:2.3:a:adobe:connect_desktop_application:2024.8.120
-
cpe:2.3:a:adobe:connect_desktop_application:2024.9.149
-
cpe:2.3:a:adobe:connect_desktop_application:2025.5.5
-
cpe:2.3:a:adobe:connect_desktop_application:2025.8.189
-
-
cpe:2.3:o:microsoft:windows:-