DOM-Based Cross-Site Scripting Vulnerability in Adobe Experience Manager
CVE-2026-71357
5.4MEDIUM
Key Information:
- Vendor
Adobe
- Status
- Vendor
- CVE Published:
- 8 September 2026
What is CVE-2026-71357?
Adobe Experience Manager is vulnerable to a DOM-based Cross-Site Scripting (XSS) flaw, allowing attackers to manipulate the DOM environment. This enables the execution of malicious JavaScript in the context of the victim's browser. To exploit this vulnerability, an attacker must lure the victim into visiting a specially crafted webpage, which triggers the execution of the script.
Affected Version(s)
Adobe Experience Manager 6.5 0 <= 6.5.24
Adobe Experience Manager 6.5 LTS 0
Adobe Experience Manager as a Cloud Service 0 <= 2026.7.0