Stored Cross-Site Scripting Vulnerability in Adobe Experience Manager
CVE-2026-75644
5.4MEDIUM
Key Information:
- Vendor
Adobe
- Status
- Vendor
- CVE Published:
- 8 September 2026
What is CVE-2026-75644?
Adobe Experience Manager is vulnerable to a stored Cross-Site Scripting (XSS) flaw, allowing low-privileged attackers to insert harmful scripts into specific form fields. This vulnerability can result in the execution of malicious JavaScript in the browsers of users visiting affected pages, potentially compromising sensitive data or leading to further attacks. Proper input validation and sanitization measures are essential to mitigate this risk.
Affected Version(s)
Adobe Experience Manager 6.5 0 <= 6.5.24
Adobe Experience Manager 6.5 LTS 0
Adobe Experience Manager as a Cloud Service 0 <= 2026.7.0