Adobe Connect SQL Injection Flaw CVE-2026-75682 Scores 9.9, Enables Code Execution
A critical SQL injection vulnerability, CVE-2026-75682, has been identified in Adobe Connect and its Android mobile app, carrying a CVSS v3 score of 9.9 — the highest among nine flaws addressed in Adobe's APSB26-150 bulletin. The flaw allows an attacker with only a low-privileged account to achieve arbitrary code execution, without requiring any user interaction. Adobe has released fixes in Connect version 12.12 and Android app version 4.5, and has stated it is unaware of any active exploitation at this time. The low-privilege requirement is considered a weak barrier, as Connect deployments routinely grant accounts to instructors, contractors, students, and external partners — any of whom could satisfy the attack precondition. Security researchers recommend patching immediately, disabling dormant accounts, restricting network access to the Connect service, and monitoring for anomalous process or database activity while updates are applied.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in