DOM-based Cross-Site Scripting Vulnerability in Adobe Experience Manager
CVE-2026-75640

5.4MEDIUM

What is CVE-2026-75640?

Adobe Experience Manager is susceptible to a DOM-based Cross-Site Scripting vulnerability, which could allow an attacker to execute malicious JavaScript code within a victim's browser. This exploit requires the target user to visit a specially crafted webpage, thereby manipulating the DOM environment. It is crucial for users to exercise caution to avoid such threats and ensure optimal security practices are maintained.

Affected Version(s)

Adobe Experience Manager 6.5 0 <= 6.5.24

Adobe Experience Manager 6.5 LTS 0

Adobe Experience Manager as a Cloud Service 0 <= 2026.7.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.