Junglewise Threat Intelligence

CVE-2026-75707: Adobe Experience Manager DOM-based cross-site scripting

CVE-2026-75707 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a widely used content management system, contains a DOM-based cross-site scripting (XSS) vulnerability that could allow attackers to execute malicious code in a user's browser. An attacker would need to trick a user into visiting a specially crafted webpage to trigger the vulnerability. Successful exploitation could lead to session hijacking, credential theft, or other malicious actions performed on behalf of the user within their Experience Manager environment.

Technical details

This is a DOM-based XSS vulnerability in Adobe Experience Manager where an attacker manipulates the Document Object Model environment to execute arbitrary JavaScript within the victim's browser context. The vulnerability requires user interaction—specifically, the victim must visit a malicious webpage—making it a network-based attack vector. The scope of impact has been changed, suggesting escalated privileges or broader affected functionality. No patch availability information is available from the provided advisory references.

Affected products

  • Adobe Experience Manager <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References