CVE-2026-34615

moderate-risk
Published 2026-04-14

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

Do I need to act?

~
3.6% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
9
CVSS 9.3/10 Critical
NETWORK / LOW complexity

Affected Products (3)

Connect Desktop Application
Connect Desktop Application

Affected Vendors

47
/ 100
moderate-risk
Severity 31/34 · Critical
Exploitability 7/34 · Low
Exposure 9/34 · Low