Adobe Connect Patches Three Critical Stored XSS Flaws Enabling Privilege Escalation
Adobe's September 2026 security release for Connect addresses three critical stored cross-site scripting vulnerabilities — CVE-2026-75684, CVE-2026-75689, and CVE-2026-75697 — each scoring 9.3 on the CVSS v3 scale. Unlike reflected XSS, these stored flaws persist within the application and can execute malicious payloads against any user who later visits an affected page, including administrators. Because the exploit runs within a privileged browser session, it can effectively grant attackers the same permissions as the signed-in user without requiring any authentication. The complete fix is available in Adobe Connect version 12.12, accompanied by Android client version 4.5. A ZoomEye scan identified over 23,600 publicly reachable Adobe Connect instances, highlighting the broad potential exposure across the internet.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in