Six Critical Flaws in Adobe Connect Could Let Attackers Take Over Accounts
Two of the worst bugs require no action from the victim. Adobe wants patches applied within 30 days, but one score of 9.9 makes that window feel generous.

Key points
- Adobe published patches on a Tuesday in September 2026, fixing nine flaws in Adobe Connect, six of them rated critical.
- Two of those critical flaws, CVE-2026-75682 and CVE-2026-75684, carry CVSS scores of 9.9 and 9.3 respectively, both without needing any action from the target.
- A third critical flaw, CVE-2026-75686 (CVSS 9.3), lets an attacker run malicious code if a victim visits a specially crafted web page.
- Adobe's own priority rating is "2", meaning the company wants patches applied within 30 days, not immediately, because no active exploitation has been reported.
- Adobe Connect patches also cover three high-severity flaws; separate critical issues were fixed the same day in Adobe Experience Manager Forms.
Adobe Connect is a web-based platform used by businesses and government agencies to run online meetings, training sessions, and webinars. Adobe issued a security update fixing nine vulnerabilities in it, six at the critical level. That's the highest possible classification.
What can the worst flaws actually do?
The most serious bugs give an attacker a path to full account takeover or arbitrary code execution, no password required and no warning to the victim.
CVE-2026-75682, scored 9.9 out of 10, is an SQL injection flaw. SQL (Structured Query Language) is the standard way software talks to its database, the back-end store that holds user records and session data. An injection flaw means an attacker can slip rogue instructions into that conversation and make the database obey them instead. A low-privileged attacker, someone with only a basic account, can exploit this one without any interaction from their target.
CVE-2026-75684, scored 9.3, is a stored cross-site scripting bug. Cross-site scripting, or XSS, is where an attacker plants malicious code inside a website so that the next person who loads that page unknowingly runs it in their browser. "Stored" means the malicious code sits permanently in a form field on the server. Anyone who views the affected page can have their session hijacked. We've tracked eight SQL injection stories in the last 90 days, starting 20 July 2026, so this class of bug is not slowing down.
CVE-2026-75686, also 9.3, is an input-validation failure. Land on a rigged web page and the software executes whatever code the attacker chose. This one does need a victim to click something, unlike the first two.
| CVE ID | Flaw type | CVSS | User interaction needed |
|---|---|---|---|
| CVE-2026-75682 | SQL injection | 9.9 | No |
| CVE-2026-75684 | Stored XSS | 9.3 | No |
| CVE-2026-75686 | Input validation | 9.3 | Yes |
Three more critical flaws (CVE-2026-75689, CVE-2026-75697, CVE-2026-75698) cover related SQL injection and scripting weaknesses. The update also fixes three high-severity bugs covering path traversal (an attacker reading files they shouldn't reach), certificate validation failures, and additional XSS issues.
Should Connect users be worried right now?
Adobe says it's found no evidence of these bugs being exploited in the wild. A 9.9-scored flaw that requires no victim interaction is exactly the kind of thing criminal groups begin probing as soon as a patch goes public, because the patch itself tells them where to look. Our reporting on the WordPress 7.1.2 flaw on 24 September 2026 showed how fast that window closes.
Adobe's priority-2 rating asks administrators to apply the update within 30 days. Given the severity of CVE-2026-75682, waiting the full 30 days is a gamble worth skipping. The same release also patched critical issues in Adobe Experience Manager Forms, reported by SecurityWeek, plus high- and medium-severity bugs in InDesign, Content Credentials SDK, Bridge, Substance 3D Modeler, and Premiere Pro.
If you use Adobe Connect through your employer or school, the platform's administrator carries the patching responsibility. If you are that administrator, Adobe's security bulletins page at helpx.adobe.com has the full details. The CVE-2026-75682 scoring alone makes this a patch-this-week job.



