---
cve: "CVE-2026-83964"
severity: "MEDIUM"
cvss: 6.2
epss: "0.2%"
vendor: "Adobe"
kev: false
exploited: false
published: "2026-09-22 19:16:54"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-10-01T03:48:45+02:00"
---

# CVE-2026-83964

> 6.2 MEDIUM

## Beschreibung

Adobe Connect is affected by an Improper Certificate Validation vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue does not require user interaction.

## CNA-Record (Kanon, cvelistV5)

- CNA: **adobe**
- State: PUBLISHED
- Stand: 2026-09-26 22:51:22
- CNA-CVSS: **6.2** (`CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N`)

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **none**
  - Automatable: **yes**
  - Technical Impact: **partial**

## CVSS-Vektor

```
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Keine | good |
| A Verfügbarkeit | Keine | good |

## BSI-Hinweise (deutsch)

- [Adobe Connect: Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/sicherheitshinweis/WID-SEC-W-2026-3516) — _BSI-Einstufung: hoch_
  Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Adobe Connect ausnutzen, um einen SQL-Injection Angriff durchzuführen, um einen Cross-Site Scripting Angriff durchzuführen, um beliebigen Programmcode auszuführen, um Informationen offenzulegen und um Sicherheitsvorkehrungen zu umgehen.

## Referenzen

- <https://helpx.adobe.com/security/products/connect/apsb26-150.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-83964) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
