Junglewise Threat Intelligence

CVE-2026-75637: Adobe Experience Manager DOM-based cross-site scripting

CVE-2026-75637 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a widely-used content management system for enterprises, is affected by a DOM-based cross-site scripting (XSS) vulnerability. An attacker could craft a malicious webpage that, when visited by a victim, executes arbitrary JavaScript in the victim's browser within the Experience Manager context, potentially leading to session hijacking, credential theft, or unauthorized actions on behalf of the victim.

Technical details

This is a DOM-based XSS vulnerability in Adobe Experience Manager, a vulnerability class where untrusted data flows through the DOM without proper sanitization. The attack requires user interaction—specifically, a victim must visit a crafted webpage containing the malicious payload. Because the scope is changed (as noted in the advisory), the vulnerability may allow an attacker to access or modify resources beyond the vulnerable component's original security boundary. No patch information is currently available in the provided references.

Affected products

  • Adobe Experience Manager <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References