Skip to content
Patchday: Adobe Connect vulnerable on Android, macOS, and Windows

Patchday: Adobe Connect vulnerable on Android, macOS, and Windows

Heise.De • September 23, 2026

Attackers can exploit “ critical ” vulnerabilities in Adobe Bridge, Connect, Content Credentials, Experience Manager Forms JEE, InDesign, Premiere Pro, and Substance 3D Modeler. In the worst case, systems are considered fully compromised after successful attacks.

In the security section of the Adobe website , the developers list the affected applications. There, administrators can also find specific information on the patched versions. The software manufacturer assures that it is not aware of any ongoing attacks. Nevertheless, administrators should not delay patching.

According to a security advisory , Connect is vulnerable through seven “ critical ” security flaws. One of them, with a CVSS score of 9.9, narrowly misses the maximum rating of 10 (CVE-2026-75682). If attackers successfully exploit the vulnerabilities, they can push and execute malicious code on computers. They can also gain higher user privileges (e.g., CVE-2026-75684). How such attacks could proceed is not yet known.

According to the developers, the versions for Android, macOS, and Windows are threatened. They state that they have resolved the security issues in Connect 12.12 (macOS, Windows) and Connect Android Mobile App 4.5 .

Adobe Experience Manager Forms (AEM Forms) is also vulnerable through “critical” code execution vulnerabilities (e.g., CVE-2026-75745). All platforms are said to be threatened. AEM 6.5 LTS Forms Service Pack 3 and AEM 6.5 Forms 6.5.25 (AEMForms-6.5.0-0134 Hotfix) have been repaired.

The remaining applications are also susceptible to code execution attacks. However, attackers can also trigger crashes (DoS) or bypass security features.

Since July of this year , Adobe has been releasing security patches for download twice a month.

This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.

Extracted Entities