Junglewise Threat Intelligence

CVE-2026-75661: Adobe Experience Manager DOM-based cross-site scripting

CVE-2026-75661 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a widely-used content management and digital experience platform, contains a cross-site scripting (XSS) vulnerability in its DOM handling. An attacker could trick a user into visiting a malicious webpage that exploits this flaw to run unauthorized scripts in the user's browser, potentially stealing session data, credentials, or sensitive content managed within Experience Manager.

Technical details

This is a DOM-based cross-site scripting (XSS) vulnerability in Adobe Experience Manager that arises from improper sanitization or validation of user-controlled data in the DOM environment. The vulnerability requires user interaction—specifically, the victim must visit a crafted webpage or click a malicious link. Once triggered, an attacker can execute arbitrary JavaScript in the context of the victim's authenticated Experience Manager session, potentially leading to session hijacking, credential theft, or manipulation of published content. The reported CVSS score is 5.4 (medium severity), and no active exploitation in the wild has been documented at the time of publication.

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed

References