Junglewise Threat Intelligence

CVE-2026-75696: Adobe Experience Manager DOM-based cross-site scripting

CVE-2026-75696 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager is a content management platform used by enterprises to create, manage, and deliver digital content. A DOM-based cross-site scripting vulnerability allows attackers to inject malicious JavaScript code that executes in a victim's browser when they visit a crafted webpage, potentially stealing session tokens, credentials, or performing unauthorized actions on behalf of the user.

Technical details

This is a DOM-based cross-site scripting (XSS) vulnerability in Adobe Experience Manager where user-controlled input is unsafely processed by client-side JavaScript code. The vulnerability requires user interaction—specifically, a victim must visit a malicious webpage crafted by an attacker. The attacker can manipulate the DOM environment to inject and execute arbitrary JavaScript within the victim's browser context, potentially allowing session hijacking, credential theft, or malicious actions performed in the user's account. A patch has been released as of the advisory publication date (September 2026).

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed: CVE-2026-75696 published

References