Adobe Connect Deserialization Vulnerability Leading to Arbitrary Code Execution

Vulnerability

A deserialization vulnerability allowing arbitrary code execution has been identified in Adobe Connect versions through 2025.9.15 and 2025.8.157. This vulnerability arises from the deserialization of untrusted data, which could be exploited by an attacker to execute arbitrary code in the context of the current user. Exploitation requires user interaction, such as visiting a maliciously crafted URL or engaging with a compromised web page.

Impact

Exploitation of this vulnerability could lead to arbitrary code execution on the affected user's system.

Remediation

Users are advised to update to Adobe Connect version 2026.3.125 for Windows or 2026.01.39 for macOS.

Added: May 12, 2026, 9:10 PM
Updated: May 12, 2026, 9:10 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
7.5
exploitability
6.4
remediation
7.7
relevance
8.1
threat
0.1
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.