Vulnerability
Published 2026-09-22
Verified 2026-09-27

Adobe Connect APSB26-150: six Critical incl. SQLi CVE-2026-75682 (CVSS 9.9); patch 12.11.1 / 12.12

Adobe Connect security update APSB26-150 (CVE records published 22 September 2026; SecurityWeek amplify 23 Sep) fixes nine defects including six Critical issues enabling arbitrary code execution / privilege escalation: CVE-2026-75682 (SQLi, Adobe CVSS 3.1 9.9), CVE-2026-75684, CVE-2026-75686, CVE-2026-75689, CVE-2026-75697, CVE-2026-75698 (SQLi / XSS / improper input validation family), plus High path-traversal, certificate-validation and XSS issues. Affected: Adobe Connect 12.11 and Android Mobile App 4.4. Unaffected/fixed: Connect 12.11.1 and 12.12; Android app 4.5. Priority 2 (apply within 30 days). Adobe states no known in-the-wild exploitation for these flaws. Same Tuesday drop also shipped AEM Forms JEE APSB26-151 (separate desk card). Primary vendor bulletin URL (helpx APSB26-150); metadata: CVE.report CVE-2026-75682; wire: SecurityWeek 23 Sep 2026.

Product
Adobe Connect (desktop/web) and Adobe Connect Android Mobile App
Versions
Affected: Connect 12.11; Android app 4.4. Patch to Connect 12.11.1 or 12.12; Android app 4.5.
CVSS
(CVE-2026-75682 CVSS 3.1 Critical, Adobe)
Exploited in Australia?
unknown
Patch to
Upgrade Adobe Connect to 12.11.1 or 12.12 and Android app to 4.5 (APSB26-150 Priority 2)

Primary: Adobe APSB26-150 — Connect security update (22 Sep 2026 CVE publish) · Vendor: Adobe — APSB26-150 · CVE: CVE-2026-75682, CVE-2026-75684, CVE-2026-75686, CVE-2026-75689, CVE-2026-75697, CVE-2026-75698 · CVE.report — CVE-2026-75682; also SecurityWeek 23 Sep 2026

vulnerabilities cloud identity