DOM-Based Cross-Site Scripting in Adobe Experience Manager
CVE-2026-75678
5.4MEDIUM
Key Information:
- Vendor
Adobe
- Status
- Vendor
- CVE Published:
- 8 September 2026
What is CVE-2026-75678?
Adobe Experience Manager is susceptible to a DOM-based Cross-Site Scripting (XSS) vulnerability, enabling attackers to exploit the DOM environment. This vulnerability allows for the execution of malicious JavaScript in the context of an unsuspecting user's browser. To successfully exploit this issue, a target user must be lured into visiting a specially crafted webpage that triggers the vulnerability, potentially compromising their security and privacy.
Affected Version(s)
Adobe Experience Manager 6.5 0 <= 6.5.24
Adobe Experience Manager 6.5 LTS 0
Adobe Experience Manager as a Cloud Service 0 <= 2026.7.0