Junglewise Threat Intelligence

CVE-2025-64610: Adobe Experience Manager stored XSS in form fields

CVE-2025-64610 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a widely-used content management and digital experience platform, contains a stored cross-site scripting vulnerability in form field handling. A low-privileged user can inject malicious scripts that execute in the browsers of other users who view the affected form, potentially leading to account takeover, credential theft, or unauthorized actions performed on behalf of legitimate users.

Technical details

The vulnerability is a stored XSS (CWE-79) affecting form field input validation in Adobe Experience Manager. A low-privileged attacker can inject malicious JavaScript into vulnerable form fields; the script is stored server-side and executed in victims' browsers when they access pages containing the poisoned field. The scope is changed, indicating the attacker may impact other users or components. No special network access or user interaction beyond browsing is required on the victim side. Patches should be available from Adobe's security advisory APSB26-98.

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: advisory: Adobe Security Bulletin APSB26-98

References