---
id: CVE-2026-75712
title: >-
  Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS)
  vulnerability
summary: >-
  Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS)
  vulnerability. An attacker could exploit this issue by manipulating the DOM
  environment to execute malicious JavaScript within the context of the victim's
  bro…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: adobe
product: experience_manager
affected:
  - experience_manager < 6.5.25.0
  - experience_manager < 2026.8.0
  - experience_manager = 6.5
patched:
  - experience_manager 2026.8.0
published: '2026-09-08'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T13:51:39.023'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-75712'
references:
  - url: >-
      https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html
    label: psirt@adobe.com
tags:
  - nvd
  - cve.org
epss: 0.00255
epssPercentile: 0.17367
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-09T17:33:43.866095Z'
ingestedAt: '2026-09-08T20:10:03.218Z'
---

## Overview

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

## Affected

- `experience_manager < 6.5.25.0`
- `experience_manager < 2026.8.0`
- `experience_manager = 6.5`

## Remediation

Upgrade past the affected range:

- `experience_manager 2026.8.0`
