DOM-based Cross-Site Scripting Vulnerability in Adobe Experience Manager
CVE-2026-75666
5.4MEDIUM
Key Information:
- Vendor
Adobe
- Status
- Vendor
- CVE Published:
- 8 September 2026
What is CVE-2026-75666?
Adobe Experience Manager is susceptible to a DOM-based Cross-Site Scripting (XSS) vulnerability, enabling attackers to exploit the DOM environment. This flaw allows for the execution of malicious JavaScript within the user's browser context. Successful exploitation necessitates user interaction, as the victim must navigate to a specially crafted webpage. This manipulation alters the scope of the attack, presenting serious security risks to users.
Affected Version(s)
Adobe Experience Manager 6.5 0 <= 6.5.24
Adobe Experience Manager 6.5 LTS 0
Adobe Experience Manager as a Cloud Service 0 <= 2026.7.0