Junglewise Threat Intelligence

CVE-2026-75635: Adobe Experience Manager DOM-based cross-site scripting

CVE-2026-75635 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a widely-used content management system for building and managing digital experiences, contains a DOM-based cross-site scripting (XSS) vulnerability. An attacker could craft a malicious webpage that, when visited by a victim, injects and executes malicious JavaScript code within the user's browser session, potentially allowing unauthorized actions on the victim's behalf or theft of sensitive information.

Technical details

This is a DOM-based cross-site scripting (XSS) vulnerability in Adobe Experience Manager where an attacker can manipulate the DOM environment to inject malicious JavaScript. The vulnerability requires user interaction—a victim must visit or be redirected to a crafted webpage. Once executed, the malicious script runs in the victim's browser with the privileges of their authenticated session, allowing potential session hijacking, credential theft, or unauthorized content modification. The scope change indicates this may affect more than the original component. Users should apply the available security patch from Adobe (APSB26-98).

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed

References