Junglewise Threat Intelligence

CVE-2026-75700: Adobe Experience Manager DOM-based cross-site scripting

CVE-2026-75700 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a widely-used platform for managing digital content and customer experiences, contains a DOM-based cross-site scripting (XSS) vulnerability. An attacker could craft a malicious webpage that, when visited by an employee or administrator, executes unauthorized JavaScript in their browser to steal session tokens, modify content, or perform actions on their behalf. This type of attack requires the victim to click a malicious link, making it dependent on social engineering.

Technical details

This is a DOM-based cross-site scripting (XSS) vulnerability in Adobe Experience Manager where an attacker manipulates the DOM environment to inject and execute malicious JavaScript within the victim's browser context. The vulnerability requires user interaction—specifically, a victim must visit a crafted webpage. The scope is marked as changed, indicating potential for expanded impact beyond simple information disclosure. No patch availability information is currently available from the accessible advisory sources.

Affected products

  • Adobe Experience Manager <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References