Executive brief
Adobe Experience Manager, a widely-used content management and digital marketing platform, is vulnerable to a DOM-based cross-site scripting (XSS) attack. An attacker could craft a malicious webpage that, when visited by an Experience Manager user, executes unauthorized JavaScript code in the user's browser session, potentially stealing credentials, session tokens, or sensitive content data.
Technical details
The vulnerability is a DOM-based cross-site scripting (XSS) issue in Adobe Experience Manager that allows an attacker to manipulate the DOM environment to inject and execute malicious JavaScript within a victim's browser context. Exploitation requires user interaction—the victim must visit a crafted webpage. The attack changes the scope of what an attacker can affect, enabling potential session hijacking, data exfiltration, or defacement of user-facing content. Patches are expected from Adobe as indicated by the APSB26-98 security bulletin reference.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed