Junglewise Threat Intelligence

CVE-2026-75651: Adobe Experience Manager DOM-based XSS

CVE-2026-75651 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a content management system used by enterprises to create and manage digital experiences, is vulnerable to a DOM-based Cross-Site Scripting (XSS) attack. An attacker could craft a malicious webpage that, when visited by a victim, executes arbitrary JavaScript in the user's browser, potentially compromising session security, stealing credentials, or defacing content.

Technical details

This is a DOM-based XSS vulnerability in Adobe Experience Manager where the attacker can manipulate the DOM environment to inject and execute malicious JavaScript within the victim's browser context. The vulnerability requires user interaction—a victim must visit an attacker-controlled or compromised webpage containing the malicious payload. The scope is changed, meaning the vulnerability can affect security properties beyond the vulnerable component itself. No patch availability is indicated in the advisory.

Affected products

  • Adobe Experience Manager <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References