Junglewise Threat Intelligence

CVE-2026-75738: Adobe Experience Manager stored XSS in form fields

CVE-2026-75738 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a widely-used content management platform, is vulnerable to stored cross-site scripting (XSS) in form fields. A low-privileged attacker can inject malicious scripts that execute in victims' browsers when they access affected pages, potentially compromising user sessions, stealing credentials, or defacing content.

Technical details

This vulnerability is a stored XSS issue affecting Adobe Experience Manager's form field handling. A low-privileged attacker can inject malicious JavaScript into vulnerable form fields; the payload persists server-side and is executed in the browser of any user viewing the affected page. The attack requires the attacker to have some level of access to the application (low-privilege user). The scope is changed, indicating the vulnerability may affect confidentiality, integrity, or availability of the system beyond just the vulnerable component. Adobe has issued patch APSB26-98; users should consult Adobe's security advisory for affected versions and updates.

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: advisory: APSB26-98

References