Junglewise Threat Intelligence

CVE-2026-75657: Adobe Experience Manager DOM-based XSS

CVE-2026-75657 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a content management platform used by many organizations to create and manage digital experiences, is affected by a cross-site scripting (XSS) vulnerability. An attacker could craft a malicious webpage that, when visited by a user, executes arbitrary JavaScript code in their browser within the context of Experience Manager, potentially leading to unauthorized actions, session hijacking, or data theft.

Technical details

This is a DOM-based cross-site scripting (XSS) vulnerability in Adobe Experience Manager. The vulnerability allows an attacker to manipulate the DOM environment to inject and execute malicious JavaScript within a victim's browser context. Exploitation requires user interaction—the victim must visit a specially crafted webpage. The scope is changed, meaning the vulnerability affects components beyond the vulnerable component itself. A patch or update from Adobe is likely available; consult APSB26-98 for remediation guidance.

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed

References