DOM-based Cross-Site Scripting Vulnerability in Adobe Experience Manager
CVE-2026-75652
5.4MEDIUM
Key Information:
- Vendor
Adobe
- Status
- Vendor
- CVE Published:
- 8 September 2026
What is CVE-2026-75652?
Adobe Experience Manager is vulnerable to a DOM-based Cross-Site Scripting (XSS) attack, which allows an attacker to manipulate the Document Object Model (DOM) within the user's browser. This vulnerability could be exploited by tricking users into visiting a specially crafted webpage that executes malicious JavaScript in the context of that user's session. User interaction is essential for exploitation, highlighting the need for vigilance when navigating unknown web resources.
Affected Version(s)
Adobe Experience Manager 6.5 0 <= 6.5.24
Adobe Experience Manager 6.5 LTS 0
Adobe Experience Manager as a Cloud Service 0 <= 2026.7.0