BlackTreeCVE IntelligenceAdobe · APSB26-98
Linked CVE review
Update Adobe Experience Manager to the fixed Adobe release
- Linked CVEs
- 109
- Confirmed exploited
- 0
- PoC or lab evidence
- 2
- Maximum CVSS
- 9.9
Confirmed exploitation, public exploit material, EPSS probability and CVSS severity answer different questions. “No confirmation recorded” means the checked sources do not currently confirm exploitation. It is not proof that exploitation has not occurred.
| CVE and description | Severity | Exploit reality | Forecast and access | Remediation |
|---|---|---|---|---|
CVE-2025-66516 PoC or lab evidence Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affectedCritical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. This CVE covers the same vulnerability as in CVE-2025-54988. However, this CVE expands the scope of affected packages in two ways. First, while the entrypoint for the vulnerability | 8.4 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.Public exploit referencedCISA Vulnrichment records proof-of-concept exploitation in its SSVC data. BlackTree has not independently executed or validated exploit material. | EPSS: 89.0% · 99.8th percentileForecast date: 2026-10-05LOCAL · LOW complexity · NONE privileges · NONE user interaction | Within 7 daysHigh technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data. |
CVE-2026-18401 PoC or lab evidence jackson-core: Number length constraint bypass in non-blocking (async) JSON parser leads to potential denial of serviceThe non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default: 1000 characters). An attacker able to submit JSON to an application that uses the async parser API can supply a number token of arbitrary length, leading to excessive memory allocation and potential CPU exhaustion, resulting in a denial of service. The synchronous pars | 6.9 · CVSS 4.0 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.Public exploit referencedCISA Vulnrichment records proof-of-concept exploitation in its SSVC data. BlackTree has not independently executed or validated exploit material. | EPSS: 0.41% · 32.8th percentileForecast date: 2026-10-05NETWORK · LOW complexity · NONE privileges · NONE user interaction | Within 7 daysMedium technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.Patch available. 2.18.6; 2.21.1; 3.1.0 |
CVE-2026-19232 Critical technical severity Adobe Experience Manager | Incorrect Authorization (CWE-863)Adobe Experience Manager is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. A low-privileged attacker could exploit this vulnerability to gain elevated access or control over the victim's account or session. Exploitation of this issue does not requ | 9.9 · CVSS 3.1 · CriticalSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.58% · 46.1th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · NONE user interaction | Within 7 daysCritical technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-27238 Scheduled assessment InDesign Desktop | Heap-based Buffer Overflow (CWE-122)InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | 7.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.34% · 24.9th percentileForecast date: 2026-10-05LOCAL · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. InDesign Desktop: 21.3, 20.5.3 |
CVE-2026-27222 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.63% · 48.3th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. Adobe Experience Manager as a Cloud Service: 2026.8.0; Adobe Experience Manager 6.5 LTS: SP3; Adobe Experience Manager 6.5: 6.5.25 |
CVE-2026-27258 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.63% · 48.3th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. Adobe Experience Manager as a Cloud Service: 2026.8.0; Adobe Experience Manager 6.5 LTS: SP3; Adobe Experience Manager 6.5: 6.5.25 |
CVE-2026-75726 Scheduled assessment Adobe Experience Manager | Improper Input Validation (CWE-20)Adobe Experience Manager is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized limited write access. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. | 3.5 · CVSS 3.1 · LowSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.54% · 43.3th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledLow technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-27227 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.39% · 30.8th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-71440 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.39% · 30.8th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. Adobe Experience Manager as a Cloud Service: 2026.8.0; Adobe Experience Manager 6.5 LTS: SP3; Adobe Experience Manager 6.5: 6.5.25 |
CVE-2026-75642 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.39% · 30.8th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. Adobe Experience Manager as a Cloud Service: 2026.8.0; Adobe Experience Manager 6.5 LTS: SP3; Adobe Experience Manager 6.5: 6.5.25 |
CVE-2026-75643 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.39% · 30.8th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75644 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.39% · 30.8th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75727 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.39% · 30.8th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75729 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.39% · 30.8th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. Adobe Experience Manager as a Cloud Service: 2026.8.0; Adobe Experience Manager 6.5 LTS: SP3; Adobe Experience Manager 6.5: 6.5.25 |
CVE-2026-75730 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.39% · 30.8th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75731 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.39% · 30.8th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75733 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.39% · 30.8th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75734 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.39% · 30.8th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75735 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.39% · 30.8th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. Adobe Experience Manager as a Cloud Service: 2026.8.0; Adobe Experience Manager 6.5 LTS: SP3; Adobe Experience Manager 6.5: 6.5.25 |
CVE-2026-75736 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.39% · 30.8th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75737 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.39% · 30.8th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75738 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.39% · 30.8th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75739 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.39% · 30.8th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75740 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.39% · 30.8th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. Adobe Experience Manager as a Cloud Service: 2026.8.0; Adobe Experience Manager 6.5 LTS: SP3; Adobe Experience Manager 6.5: 6.5.25 |
CVE-2026-75741 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.39% · 30.8th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75742 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.39% · 30.8th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-79905 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.39% · 30.8th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-71356 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-71357 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-71388 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-71565 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-72626 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-72627 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75629 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75635 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. Adobe Experience Manager as a Cloud Service: 2026.8.0; Adobe Experience Manager 6.5 LTS: SP3; Adobe Experience Manager 6.5: 6.5.25 |
CVE-2026-75636 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75637 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75639 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75640 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75646 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75647 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75651 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.5th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. Adobe Experience Manager as a Cloud Service: 2026.8.0; Adobe Experience Manager 6.5 LTS: SP3; Adobe Experience Manager 6.5: 6.5.25 |
CVE-2026-75652 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75657 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75659 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75660 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75661 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. Adobe Experience Manager as a Cloud Service: 2026.8.0; Adobe Experience Manager 6.5 LTS: SP3; Adobe Experience Manager 6.5: 6.5.25 |
CVE-2026-75666 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75667 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75668 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75669 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75670 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. Adobe Experience Manager as a Cloud Service: 2026.8.0; Adobe Experience Manager 6.5 LTS: SP3; Adobe Experience Manager 6.5: 6.5.25 |
CVE-2026-75671 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75672 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75674 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75675 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75677 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. Adobe Experience Manager as a Cloud Service: 2026.8.0; Adobe Experience Manager 6.5 LTS: SP3; Adobe Experience Manager 6.5: 6.5.25 |
CVE-2026-75678 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75679 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75680 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75681 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75683 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. Adobe Experience Manager as a Cloud Service: 2026.8.0; Adobe Experience Manager 6.5 LTS: SP3; Adobe Experience Manager 6.5: 6.5.25 |
CVE-2026-75685 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.5th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75687 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75690 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.5th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75691 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75692 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. Adobe Experience Manager as a Cloud Service: 2026.8.0; Adobe Experience Manager 6.5 LTS: SP3; Adobe Experience Manager 6.5: 6.5.25 |
CVE-2026-75693 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75694 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75695 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75696 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75700 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. Adobe Experience Manager as a Cloud Service: 2026.8.0; Adobe Experience Manager 6.5 LTS: SP3; Adobe Experience Manager 6.5: 6.5.25 |
CVE-2026-75701 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75702 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75704 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75705 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.5th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75706 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. Adobe Experience Manager as a Cloud Service: 2026.8.0; Adobe Experience Manager 6.5 LTS: SP3; Adobe Experience Manager 6.5: 6.5.25 |
CVE-2026-75707 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75708 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75709 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75710 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.5th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75711 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. Adobe Experience Manager as a Cloud Service: 2026.8.0; Adobe Experience Manager 6.5 LTS: SP3; Adobe Experience Manager 6.5: 6.5.25 |
CVE-2026-75712 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75713 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75714 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75715 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75716 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. Adobe Experience Manager as a Cloud Service: 2026.8.0; Adobe Experience Manager 6.5 LTS: SP3; Adobe Experience Manager 6.5: 6.5.25 |
CVE-2026-75717 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75718 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75719 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75720 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75722 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. Adobe Experience Manager as a Cloud Service: 2026.8.0; Adobe Experience Manager 6.5 LTS: SP3; Adobe Experience Manager 6.5: 6.5.25 |
CVE-2026-75724 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-75725 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.36% · 27.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2025-64584 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.28% · 18.3th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2025-64588 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.28% · 18.3th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2025-64589 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.28% · 18.3th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2025-64610 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.28% · 18.3th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2025-64618 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.28% · 18.3th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. Adobe Experience Manager as a Cloud Service: 2026.8.0; Adobe Experience Manager 6.5 LTS: SP3; Adobe Experience Manager 6.5: 6.5.25 |
CVE-2025-64830 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.28% · 18.3th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2025-64838 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.28% · 18.3th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2025-64854 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.28% · 18.3th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2025-64866 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.28% · 18.3th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2025-64868 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.28% · 18.3th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. Adobe Experience Manager as a Cloud Service: 2026.8.0; Adobe Experience Manager 6.5 LTS: SP3; Adobe Experience Manager 6.5: 6.5.25 |
CVE-2025-64542 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.26% · 15.5th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. Adobe Experience Manager as a Cloud Service: 2026.8.0; Adobe Experience Manager 6.5 LTS: SP3; Adobe Experience Manager 6.5: 6.5.25 |
CVE-2026-19479 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.26% · 15.5th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-19612 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.26% · 15.5th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-19644 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.26% · 15.5th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. 2026.8.0; SP3; 6.5.25 |
CVE-2026-19713 Scheduled assessment Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | 5.4 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.26% · 15.5th percentileForecast date: 2026-10-05NETWORK · LOW complexity · LOW privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. Adobe Experience Manager as a Cloud Service: 2026.8.0; Adobe Experience Manager 6.5 LTS: SP3; Adobe Experience Manager 6.5: 6.5.25 |