deniz.in

Markets

Weather

Loading weather

· via dev.to (home feed)

Adobe Connect 12.12 and Android App 4.5 close nine flaws in APSB26-150

Adobe's APSB26-150 bulletin patches nine vulnerabilities in Adobe Connect and its Android app, led by a 9.9-rated SQL injection, and admins are warned not to leave mobile clients behind.

Adobe Connect 12.12 and Android App 4.5 close nine flaws in APSB26-150

What shipped

Adobe's September 2026 security bulletin APSB26-150 covers two products: the Adobe Connect meeting server and the Adobe Connect Android mobile app. The builds that resolve the issues are Adobe Connect 12.12 on the server side and Adobe Connect Android Mobile App 4.5 on the client side. According to a dev.to analysis of the bulletin, nine CVEs are fixed across the pair.

The vulnerabilities

The headline flaw is CVE-2026-75682, a SQL injection with a CVSS score of 9.9 that can lead to arbitrary code execution and is reachable with a low-privileged account. Five of the remaining flaws score 9.3, and three of those are stored cross-site scripting issues that result in privilege escalation. CVE-2026-34689 is a path traversal rated 8.6 that requires no authentication at all. The last two flaws score below 7.

Adobe said at publication that it was not aware of active exploitation of any of these flaws, the dev.to write-up reports.

Why mobile clients lag behind

Patch bulletins typically list host software first, and administrators tend to read exactly that far. The dev.to analysis argues the Android half of APSB26-150 is where deployments most often fall behind, because mobile builds reach devices through app stores, user-initiated installs or mobile device management, and none of those paths follow a server maintenance window.

Three patterns produce the version gap, according to the write-up: the server is upgraded on schedule while phones keep whatever users installed themselves; an organisation distributes the app internally and its distribution channel drifts out of sync with the store; or a contractor connects from a personally managed device that never entered inventory. The outcome is a fleet where the server is patched and a slice of the clients is not.

For a sense of scale, a ZoomEye query for the Adobe Connect fingerprint returned 23,660 instances at the time it was run. That figure counts indexed servers visible to internet scanning and says nothing about mobile installs, which asset management has to account for instead.

A two-sided upgrade plan

The write-up recommends treating the bulletin as a single remediation with two halves:

  • Confirm the current server build and upgrade to Adobe Connect 12.12.
  • Publish Android Mobile App 4.5 through the channel users actually install from.
  • Check managed device inventories for the app version, not only the operating system version.
  • Ask partners and contractors to confirm their client version if they join meetings on the environment.
  • Re-validate both server and clients after the window, since a patched server with unpatched clients is an incomplete fix.

Why it matters

APSB26-150 pairs a 9.9-rated SQL injection and an unauthenticated path traversal with a client-side update that no maintenance window will deliver on its own. Server counts in the tens of thousands make the server patch urgent, but the mobile half decides whether the fix is actually complete: the remaining exposure sits on devices the administrator does not directly control, spread across app stores, internal distribution channels and personal phones. Treating APSB26-150 as finished once Connect 12.12 ships leaves the deployment only half protected.

  • #adobe-connect
  • #security
  • #patching
  • #android
  • #vulnerability

Related posts