Skip to content
Adobe Patch Day 2026-09-22: 10 critical vulnerabilities amid 29 CVEs

Adobe Patch Day 2026-09-22: 10 critical vulnerabilities amid 29 CVEs

Feedly September 23, 2026

Adobe Connect is affected by a critical SQL injection vulnerability (CVSS 9.9) that enables low-privileged attackers to execute arbitrary code remotely without user interaction. The vulnerability allows attackers to execute arbitrary SQL commands, potentially leading to complete system compromise with high impact to confidentiality, integrity, and availability across changed scope. Immediate patching is essential as the low attack complexity and network-based attack vector make this vulnerability highly exploitable, affecting Adobe Connect versions 12.11 and earlier, as well as the Android Mobile App version 4.4 and earlier.

Adobe Connect versions 12.11 and earlier, along with Android Mobile App versions 4.4 and earlier, are affected by a reflected Cross-Site Scripting (XSS) vulnerability with a CVSS score of 9.3 (Critical) . The vulnerability allows attackers to inject malicious scripts through crafted URLs, potentially leading to high confidentiality and integrity impacts with changed scope , enabling account takeover or session hijacking. User interaction is required for exploitation, but the low attack complexity and network-based attack vector make this a significant risk requiring immediate patching to prevent potential compromise of user accounts and sensitive data.

Adobe Connect versions 12.11 and earlier, along with the Android Mobile App version 4.4 and earlier, are affected by an Improper Input Validation vulnerability with a CVSS score of 9.3 (Critical) . The vulnerability allows remote attackers to execute arbitrary code in the context of the current user through a maliciously crafted URL or compromised web page, requiring only user interaction with no privileges needed. This poses a significant risk as successful exploitation could lead to full compromise of confidentiality and integrity of affected systems, making immediate patching essential to prevent potential system compromise.

Adobe Connect versions 12.11 and earlier, along with the Android Mobile App version 4.4 and earlier, are affected by a stored Cross-Site Scripting (XSS) vulnerability with a critical CVSS score of 9.3 . Attackers can inject malicious scripts into vulnerable form fields without requiring authentication, which execute when victims browse to the affected page, potentially leading to elevated access, account compromise, or session hijacking with high confidentiality and integrity impact . Patching is critical due to the low attack complexity, network-based attack vector, and the changed scope that allows attackers to impact resources beyond the vulnerable component's security scope.

Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability with a CVSS score of 9.3 (Critical) , allowing attackers to inject malicious scripts into vulnerable form fields without requiring authentication. When victims browse to pages containing the compromised fields, the malicious JavaScript executes in their browser, potentially enabling attackers to gain elevated access or control over victim accounts and sessions with changed scope impact. This vulnerability affects Adobe Connect versions up to 12.11 and the Android Mobile App up to version 4.4, requiring immediate patching to prevent account compromise and unauthorized access to sensitive data.

Adobe Connect (versions ≤12.11) and its Android Mobile App (versions ≤4.4) are affected by a stored Cross-Site Scripting (XSS) vulnerability with a CVSS score of 9.3 (Critical) . Attackers can inject malicious scripts into vulnerable form fields that execute when victims browse to the affected page, potentially leading to account compromise, session hijacking, and unauthorized access to sensitive data with high confidentiality and integrity impact . The changed scope indicates the vulnerability can affect resources beyond the vulnerable component, making patching critical to prevent attackers from leveraging stored malicious payloads against multiple users without requiring elevated privileges.

Adobe Experience Manager Forms JEE is affected by an Improper Input Validation vulnerability (CVSS 9.1 Critical) that enables arbitrary code execution with changed scope . An attacker with high privileges can exploit this remotely over the network with low complexity and no user interaction, potentially compromising confidentiality, integrity, and availability of systems beyond the vulnerable component. Patching is critical to prevent attackers who have gained elevated access from leveraging this vulnerability to execute code and pivot to additional systems.

Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability with a CVSS score of 8.7 , enabling attackers with high privileges to achieve privilege escalation and gain elevated access to internal resources. The vulnerability has changed scope with high confidentiality and integrity impacts , allowing potential unauthorized access to sensitive data and system modifications across security boundaries. Patching is critical as exploitation requires no user interaction and can be conducted remotely over the network with low attack complexity, affecting versions up to AEM 6.5.25 and 6.5 LTS SP2.