CVE-2026-83964
CVE-2026-83964 is a medium-severity vulnerability in Adobe Connect with a CVSS 3.x base score of 6.2. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-295.
Key facts
- Severity: Medium (CVSS 3.x base score 6.2)
- EPSS exploit prediction: 0% (11th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-295
- Affected product: Adobe Connect
- Published:
- Last modified:
Description
Adobe Connect is affected by an Improper Certificate Validation vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue does not require user interaction.
Frequently asked questions
- What is CVE-2026-83964?
- Adobe Connect is affected by an Improper Certificate Validation vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue does not require user interaction.
- How severe is CVE-2026-83964?
- CVE-2026-83964 has a CVSS 3.x base score of 6.2, rated medium severity. It is exploitable over local access with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity none, and availability none.
- Is CVE-2026-83964 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (11th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-83964?
- CVE-2026-83964 primarily affects Adobe Connect. In total, 2 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2026-83964?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-83964 published?
- CVE-2026-83964 was published on 2026-09-22 and last updated on 2026-09-26.
References
Affected products (2)
- cpe:2.3:a:adobe:connect:*:*:*:*:*:-:*:*
- cpe:2.3:a:adobe:connect_for_mobile:*:*:*:*:*:android:*:*
More vulnerabilities in Adobe Connect
- CVE-2017-11291 — Critical (CVSS 10.0): An issue was discovered in Adobe Connect 9.6.2 and earlier versions. A Server-Side Request Forgery (SSRF) vulnerability…
- CVE-2026-75682 — Critical (CVSS 9.9): Adobe Connect is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')…
- CVE-2023-4662 — Critical (CVSS 9.8): Execution with Unnecessary Privileges vulnerability in Saphira Saphira Connect allows Remote Code Inclusion. This…
- CVE-2023-4661 — Critical (CVSS 9.8): Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saphira Saphira…
- CVE-2021-40719 — Critical (CVSS 9.8): Adobe Connect version 11.2.3 (and earlier) is affected by a Deserialization of Untrusted Data vulnerability to achieve…
- CVE-2018-12805 — Critical (CVSS 9.8): Adobe Connect versions 9.7.5 and earlier have an Insecure Library Loading vulnerability. Successful exploitation could…
All CVEs affecting Adobe Connect →
Other CWE-295 (Improper Certificate Validation) vulnerabilities
- CVE-2026-58162 — Critical (CVSS 10.0): The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This…
- CVE-2026-4370 — Critical (CVSS 10.0): A vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.0.4, where the…
- CVE-2026-30836 — Critical (CVSS 10.0): Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6…
- CVE-2025-68121 — Critical (CVSS 10.0): During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between…
- CVE-2022-20703 — Critical (CVSS 10.0): Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker…
- CVE-2026-78234 — Critical (CVSS 9.9): A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the…
Browse all CWE-295 (Improper Certificate Validation) vulnerabilities →