DOM-based Cross-Site Scripting Vulnerability in Adobe Experience Manager
CVE-2026-75637
5.4MEDIUM
Key Information:
- Vendor
Adobe
- Status
- Vendor
- CVE Published:
- 8 September 2026
What is CVE-2026-75637?
Adobe Experience Manager has a DOM-based Cross-Site Scripting (XSS) vulnerability that allows attackers to execute harmful JavaScript in the context of a user's browser. This exploitation requires the victim to visit a specially crafted webpage, manipulating the DOM environment to trigger the vulnerability. This poses significant security risks as it can compromise the confidentiality and integrity of user information.
Affected Version(s)
Adobe Experience Manager 6.5 0 <= 6.5.24
Adobe Experience Manager 6.5 LTS 0
Adobe Experience Manager as a Cloud Service 0 <= 2026.7.0