DOM-based Cross-Site Scripting Vulnerability in Adobe Experience Manager
CVE-2026-71565
5.4MEDIUM
Key Information:
- Vendor
Adobe
- Status
- Vendor
- CVE Published:
- 8 September 2026
What is CVE-2026-71565?
Adobe Experience Manager is impacted by a DOM-based Cross-Site Scripting (XSS) vulnerability that allows attackers to manipulate the document object model and execute harmful JavaScript within the victim's web browser. To exploit this vulnerability, attackers must lure victims into visiting a specially crafted webpage, triggering the execution of the malicious script. This highlights the importance of securing user interactions and validating content from untrusted sources.
Affected Version(s)
Adobe Experience Manager 6.5 0 <= 6.5.24
Adobe Experience Manager 6.5 LTS 0
Adobe Experience Manager as a Cloud Service 0 <= 2026.7.0