{"dataType": "CVE_RECORD", "containers": {"cna": {"metrics": [{"format": "CVSS", "cvssV3_1": {"scope": "CHANGED", "version": "3.1", "baseScore": 9.6, "attackVector": "NETWORK", "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "REQUIRED", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}}], "affected": [{"cpes": ["cpe:2.3:a:adobe:connect:*:*:*:*:*:-:*:*"], "vendor": "adobe", "product": "connect", "versions": [{"status": "affected", "version": "0", "lessThan": "12.11", "versionType": "custom"}], "platforms": ["cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*", "cpe:2.3:o:microsoft:*:*:*:*:*:*:*:*:*"], "defaultStatus": "unaffected"}, {"cpes": ["cpe:2.3:a:adobe:connect_desktop_application:*:*:*:*:*:macos:*:*"], "vendor": "adobe", "product": "connect_desktop_application", "versions": [{"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2025.3"}], "platforms": ["cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*"], "defaultStatus": "unaffected"}, {"cpes": ["cpe:2.3:a:adobe:connect_desktop_application:*:*:*:*:*:windows:*:*"], "vendor": "adobe", "product": "connect_desktop_application", "versions": [{"status": "affected", "version": "0", "lessThan": "2025.9.15", "versionType": "custom"}], "platforms": ["cpe:2.3:o:microsoft:*:*:*:*:*:*:*:*:*"], "defaultStatus": "unaffected"}], "references": [{"url": "https://helpx.adobe.com/security/products/connect/apsb26-37.html", "tags": ["vendor-advisory"]}], "descriptions": [{"lang": "en", "value": "Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed."}], "problemTypes": [{"descriptions": [{"lang": "en", "cweId": "CWE-502", "description": "CWE-502"}]}], "providerMetadata": {"orgId": "00000000-0000-4000-A000-000000000003", "shortName": "nvd", "dateUpdated": "2026-04-14T18:16:56Z", "x_subShortName": "nvd"}}}, "cveMetadata": {"cveId": "CVE-2026-27303", "state": "PUBLISHED", "dateUpdated": "2026-04-28T15:40:06Z", "assignerOrgId": "078d4453-3bcd-4900-85e6-15281da43538", "datePublished": "2026-04-14T18:16:56Z", "assignerShortName": "adobe"}, "dataVersion": "5.0"}