Junglewise Threat Intelligence

CVE-2026-75666: Adobe Experience Manager DOM-based cross-site scripting

CVE-2026-75666 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a content management platform used by enterprises to build and manage digital experiences, is vulnerable to a DOM-based cross-site scripting (XSS) attack. An attacker could trick a user into visiting a malicious webpage to execute arbitrary JavaScript code in their browser, potentially compromising sensitive content or user credentials within the Experience Manager environment.

Technical details

The vulnerability is a DOM-based cross-site scripting (XSS) flaw in Adobe Experience Manager that allows an attacker to inject and execute malicious JavaScript in a victim's browser. The attack requires user interaction—specifically, the victim must be tricked into visiting a crafted webpage. The attacker manipulates the DOM environment to execute the malicious script within the security context of the user's session. The scope of the vulnerability has been elevated, meaning the attacker can impact resources beyond the vulnerable component itself. A patch or update is recommended; consult Adobe security advisories (APSB26-98) for availability.

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed

References