Junglewise Threat Intelligence

CVE-2026-75719: Adobe Experience Manager DOM-based cross-site scripting

CVE-2026-75719 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a content management and digital asset platform, contains a DOM-based cross-site scripting (XSS) vulnerability. An attacker could craft a malicious webpage that, when visited by a user, executes arbitrary JavaScript in their browser within the context of the application, potentially compromising the user's session, stealing credentials, or modifying page content.

Technical details

The vulnerability is a DOM-based cross-site scripting (XSS) flaw in Adobe Experience Manager. The vulnerability allows an attacker to manipulate the DOM environment to inject and execute malicious JavaScript code. Exploitation requires user interaction—a victim must visit a crafted webpage or link. The scope is changed, indicating impact beyond the vulnerable component itself. The vulnerability has been assigned CVE-2026-75719 with a CVSS score of 5.4 (medium severity). No patch or mitigation details are currently available from the provided reference materials.

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed

References