DOM-Based Cross-Site Scripting Vulnerability in Adobe Experience Manager
CVE-2026-75661
5.4MEDIUM
Key Information:
- Vendor
Adobe
- Status
- Vendor
- CVE Published:
- 8 September 2026
What is CVE-2026-75661?
Adobe Experience Manager is vulnerable to a DOM-based Cross-Site Scripting (XSS) flaw that allows attackers to execute malicious JavaScript within the victim's browser. This vulnerability occurs when user interaction leads to the manipulation of the Document Object Model (DOM), allowing unauthorized scripts to run in the context of the user's session. Exploiting this vulnerability necessitates that victims visit a specially crafted webpage, which can result in various security risks including data theft and unauthorized actions performed in the context of the user.
Affected Version(s)
Adobe Experience Manager 6.5 0 <= 6.5.24
Adobe Experience Manager 6.5 LTS 0
Adobe Experience Manager as a Cloud Service 0 <= 2026.7.0