May 2026 Patch TuesdayAPSB26-50Normal patch window

Adobe · APSB26-50

Linked CVE review

Update Adobe Connect to the fixed Adobe release

Linked CVEs
2
Confirmed exploited
0
PoC or lab evidence
0
Maximum CVSS
9.6
Evidence is kept separate

Confirmed exploitation, public exploit material, EPSS probability and CVSS severity answer different questions. “No confirmation recorded” means the checked sources do not currently confirm exploitation. It is not proof that exploitation has not occurred.

Reset
2 of 2 linked CVEs shown
Confirmed exploitedCVSS above 9.0
CVE and descriptionSeverityExploit realityForecast and accessRemediation
CVE-2026-34659 Critical technical severity
Adobe Connect | Deserialization of Untrusted Data (CWE-502)

Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web p

9.6 · CVSS 3.1 · CriticalSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 1.87% · 78.6th percentileForecast date: 2026-10-05NETWORK · LOW complexity · NONE privileges · REQUIRED user interactionWithin 7 daysCritical technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. 12.11.1; 2026.3.125 (Win), 2026.01.39 (Mac)
CVE-2026-34660 Critical technical severity
Adobe Connect | Incorrect Authorization (CWE-863)

Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interact

9.3 · CVSS 3.1 · CriticalSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 1.03% · 62.5th percentileForecast date: 2026-10-05NETWORK · LOW complexity · NONE privileges · REQUIRED user interactionWithin 7 daysCritical technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. 12.11.1; 2026.3.125 (Win), 2026.01.39 (Mac)