πŸ” CVE Alert

CVE-2026-27237

MEDIUM 5.4

Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CWE CWE-79
Vendor adobe
Product adobe experience manager as a cloud service
Ecosystems
Industries
TechnologyMedia
Published Mar 11, 2026
Last Updated Aug 27, 2026
Stay Ahead of the Next One

Get instant alerts for adobe adobe experience manager as a cloud service

Be the first to know when new medium vulnerabilities affecting adobe adobe experience manager as a cloud service are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

Adobe / Adobe Experience Manager as a Cloud Service
0 ≀ 2026.1.0
Adobe / Adobe Experience Manager 6.5 LTS
0 ≀ SP1
Adobe / Adobe Experience Manager 6.5
0 ≀ 6.5.23

References

NVD β†— CVE.org β†— EPSS Data β†—
helpx.adobe.com: https://helpx.adobe.com/security/products/experience-manager/apsb26-24.html