Junglewise Threat Intelligence

CVE-2026-75646: Adobe Experience Manager DOM-based XSS vulnerability

CVE-2026-75646 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a widely-used content management platform, contains a DOM-based cross-site scripting (XSS) vulnerability that could allow attackers to execute malicious code in the browsers of users who visit a specially crafted webpage. This vulnerability requires user interaction and could lead to session hijacking, credential theft, or unauthorized actions performed on behalf of the victim within Experience Manager.

Technical details

This is a DOM-based XSS vulnerability in Adobe Experience Manager where an attacker can manipulate the DOM environment to execute arbitrary JavaScript in the victim's browser context. The vulnerability requires user interaction—specifically, a victim must visit a crafted webpage. The scope is changed, indicating a potential impact beyond the vulnerable component itself. No information on available patches or workarounds is currently available from the provided reference materials.

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed

References