Junglewise Threat Intelligence

CVE-2026-75709: Adobe Experience Manager DOM-based XSS

CVE-2026-75709 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a content management platform used by enterprises to create and manage digital experiences, is affected by a DOM-based cross-site scripting vulnerability. An attacker could trick a user into visiting a malicious webpage to execute arbitrary JavaScript code in their browser within the context of Experience Manager, potentially leading to session hijacking, credential theft, or unauthorized actions on behalf of the victim.

Technical details

This is a DOM-based cross-site scripting (XSS) vulnerability in Adobe Experience Manager. The vulnerability is exploited by manipulating the DOM environment to inject and execute malicious JavaScript code within the context of a victim's browser session. Successful exploitation requires user interaction—specifically, the victim must visit a crafted webpage. The scope of the vulnerability is changed, indicating it may affect confidentiality, integrity, or availability beyond the vulnerable component itself. No indication of active exploitation in the wild or availability of patches is documented at this time.

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed

References