CVE-2026-27246 - Vulnerability Analysis
CriticalCVSS: 9.3Last Updated: April 14, 2026
Adobe Connect - Stored XSS
Published: April 14, 2026Updated: April 14, 2026Remote Exploitable
Overview
Adobe Connect <= 2025.3, 12.10 contains a DOM-based cross-site scripting vulnerability caused by manipulation of the DOM environment, letting attackers execute malicious JavaScript in victim's browser, exploit requires user interaction.
Severity & Score
Severity: Critical
CVSS Score: 9.3
Impact
Attackers can execute malicious scripts in victim's browser, potentially stealing data or performing actions on behalf of the user.
Mitigation
Update to the latest version beyond 2025.3 or 12.10.
Related Resources
Details
- CVE ID
- CVE-2026-27246
- Severity
- Critical
- CVSS Score
- 9.3
- Type
- stored_xss
- Status
- new
CWE
- CWE-79
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N