Junglewise Threat Intelligence

CVE-2026-75680: Adobe Experience Manager DOM-based XSS

CVE-2026-75680 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a widely-used platform for managing digital content and customer experiences, is vulnerable to a DOM-based cross-site scripting attack. An attacker could craft a malicious webpage that, when visited by a user, executes arbitrary JavaScript in their browser with the permissions of the Experience Manager application. This could lead to session hijacking, credential theft, or unauthorized actions on behalf of the victim.

Technical details

The vulnerability is a DOM-based cross-site scripting (XSS) flaw in Adobe Experience Manager where user-controlled input is improperly sanitized before being used in DOM manipulation operations. The attack requires network access and user interaction—a victim must be tricked into visiting a crafted webpage that manipulates the DOM environment to inject and execute malicious JavaScript. Successful exploitation allows an attacker to execute arbitrary code within the security context of the victim's browser session. The vulnerability changes scope, meaning it may affect other security properties of the application. Patches are expected to be available from Adobe.

Affected products

  • Adobe Experience Manager <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References