Junglewise Threat Intelligence

CVE-2026-75681: Adobe Experience Manager DOM-based cross-site scripting

CVE-2026-75681 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a widely-used content management platform for enterprises, is vulnerable to DOM-based cross-site scripting (XSS). An attacker could craft a malicious webpage that, when visited by a user, executes arbitrary JavaScript in their browser within the context of Experience Manager, potentially leading to session hijacking, credential theft, or unauthorized actions on behalf of the victim.

Technical details

This is a DOM-based cross-site scripting (XSS) vulnerability in Adobe Experience Manager. The vulnerability is exploited by manipulating the DOM environment to execute malicious JavaScript within the victim's browser context. Exploitation requires user interaction—a victim must visit a crafted webpage to trigger the attack. The scope of the vulnerability is changed, indicating potential for impact beyond the vulnerable component itself. No patch availability information is currently available from the provided advisory.

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed

References