VDB
CVE-2026-34660
CVE-2026-34660
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
EPSS 0.31% · 54.8th percentile
Risk Scores
CVSS 3.1
9.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
EPSS Score
0.31%
54.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Adobe Connect | 0, 0, 0 |
Timeline
- May 12, 2026 CVE Published
- May 13, 2026 CVE Updated
- May 13, 2026 Security Advisory
- May 18, 2026 EPSS Score
- May 19, 2026 EPSS Score
- May 20, 2026 EPSS Score
- May 21, 2026 EPSS Score
- May 22, 2026 EPSS Score
- May 23, 2026 EPSS Score
- May 24, 2026 EPSS Score
- May 25, 2026 EPSS Score
- May 26, 2026 EPSS Score