Adobe Connect APSB26-150: six Critical incl. SQLi CVE-2026-75682 (CVSS 9.9); patch 12.11.1 / 12.12
Adobe Connect security update APSB26-150 (CVE records published 22 September 2026; SecurityWeek amplify 23 Sep) fixes nine defects including six Critical issues enabling arbitrary code execution / privilege escalation: CVE-2026-75682 (SQLi, Adobe CVSS 3.1 9.9), CVE-2026-75684, CVE-2026-75686, CVE-2026-75689, CVE-2026-75697, CVE-2026-75698 (SQLi / XSS / improper input validation family), plus High path-traversal, certificate-validation and XSS issues. Affected: Adobe Connect 12.11 and Android Mobile App 4.4. Unaffected/fixed: Connect 12.11.1 and 12.12; Android app 4.5. Priority 2 (apply within 30 days). Adobe states no known in-the-wild exploitation for these flaws. Same Tuesday drop also shipped AEM Forms JEE APSB26-151 (separate desk card). Primary vendor bulletin URL (helpx APSB26-150); metadata: CVE.report CVE-2026-75682; wire: SecurityWeek 23 Sep 2026.
- Product
- Adobe Connect (desktop/web) and Adobe Connect Android Mobile App
- Versions
- Affected: Connect 12.11; Android app 4.4. Patch to Connect 12.11.1 or 12.12; Android app 4.5.
- CVSS
- (CVE-2026-75682 CVSS 3.1 Critical, Adobe)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- Upgrade Adobe Connect to 12.11.1 or 12.12 and Android app to 4.5 (APSB26-150 Priority 2)
Primary: Adobe APSB26-150 — Connect security update (22 Sep 2026 CVE publish) · Vendor: Adobe — APSB26-150 · CVE: CVE-2026-75682, CVE-2026-75684, CVE-2026-75686, CVE-2026-75689, CVE-2026-75697, CVE-2026-75698 · CVE.report — CVE-2026-75682; also SecurityWeek 23 Sep 2026
