Adobe Patches Critical 9.9 SQL Injection in Connect 12.12 Alongside Eight Other Flaws
Adobe released a September 2026 security update for Adobe Connect that addresses nine vulnerabilities, seven of which are rated critical. The most severe flaw, CVE-2026-75682, carries a CVSS score of 9.9 and is a SQL injection vulnerability that can allow a low-privileged attacker to execute arbitrary code. Other critical issues include stored cross-site scripting bugs that enable privilege escalation and a path traversal flaw requiring no authentication or user interaction. The fixes apply to Adobe Connect 12.12 and Adobe Connect Android Mobile App 4.5, with earlier versions remaining vulnerable. Adobe stated it is not aware of any active exploitation of these vulnerabilities at the time of the advisory.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in