PatchSiren

Adobe CVE debriefs · Page 3

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-75670

CVE-2026-75670 is a DOM-based Cross-Site Scripting (XSS) vulnerability affecting Adobe Experience Manager. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. This requires user interaction, as a victim must visit a crafted webpage. The vulnerability's scope is changed, indicating potential impact on other com [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-75668

CVE-2026-75668 is a DOM-based Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager. Exploitation requires user interaction, as a victim must visit a crafted webpage. The vulnerability has a CVSS score of 5.4 and is classified as MEDIUM severity. Defenders should assess exposure, particularly for versions prior to 6.5.25.0 and 2026.8.0 for AEM Cloud Service, and prioritize patching. The vul [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-75667

CVE-2026-75667 is a DOM-based Cross-Site Scripting (XSS) vulnerability affecting Adobe Experience Manager. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation requires user interaction, as a victim must visit a crafted webpage. The vulnerability has a CVSS score of 5.4 and is classified as MEDIUM [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-75666

CVE-2026-75666 is a DOM-based Cross-Site Scripting (XSS) vulnerability affecting Adobe Experience Manager. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. This requires user interaction, as a victim must visit a crafted webpage. The vulnerability has a CVSS score of 5.4 and is classified as MEDIUM severity [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-75661

CVE-2026-75661 is a DOM-based Cross-Site Scripting (XSS) vulnerability affecting Adobe Experience Manager. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. This requires user interaction, as a victim must visit a crafted webpage. The vulnerability has a CVSS score of 5.4 and MEDIUM severity. Defenders shoul [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-75660

CVE-2026-75660 is a DOM-based Cross-Site Scripting (XSS) vulnerability affecting Adobe Experience Manager. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation requires user interaction, as a victim must visit a crafted webpage. This vulnerability has a CVSS score of 5.4 and is classified as MEDIUM [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-75659

CVE-2026-75659 is a DOM-based Cross-Site Scripting (XSS) vulnerability affecting Adobe Experience Manager. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. This requires user interaction, as a victim must visit a crafted webpage. The vulnerability has a medium severity and a CVSS score of 5.4. Defenders res [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-75657

CVE-2026-75657 is a DOM-based Cross-Site Scripting (XSS) vulnerability affecting Adobe Experience Manager. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation requires user interaction, as a victim must visit a crafted webpage. The vulnerability has a Medium CVSS score of 5.4, indicating moderate [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-75652

CVE-2026-75652 is a DOM-based Cross-Site Scripting (XSS) vulnerability affecting Adobe Experience Manager. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. This requires user interaction, as a victim must visit a crafted webpage. The vulnerability has a CVSS score of 5.4, indicating medium severity. Adminis [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-75651

CVE-2026-75651 is a DOM-based Cross-Site Scripting (XSS) vulnerability affecting Adobe Experience Manager. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. This requires user interaction, as a victim must visit a crafted webpage. The vulnerability has a CVSS score of 5.4 and MEDIUM severity. Defenders respo [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-75647

CVE-2026-75647 is a DOM-based Cross-Site Scripting (XSS) vulnerability affecting Adobe Experience Manager. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. This requires user interaction, as a victim must visit a crafted webpage. The vulnerability has a medium severity and can lead to potential execution of [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-75646

CVE-2026-75646 is a DOM-based Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. This requires user interaction, as a victim must visit a crafted webpage. The vulnerability has a CVSS score of 5.4 and a severity of MEDIUM. Affected administ [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-75644

CVE-2026-75644 is a stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager that could allow a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. This vulnerability has a CVSS score of 5.4 and a severity of MEDIUM. The vulnerability affe [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-75643

A stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager could allow a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. The vulnerability affects Adobe Experience Manager instances, and defenders should assess exposure and apply patch [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-75642

CVE-2026-75642 is a stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager that could allow a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. The vulnerability exists in Adobe Experience Manager, affecting its form fields. A low-priv [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-75640

CVE-2026-75640 is a DOM-based Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. This requires user interaction, as a victim must visit a crafted webpage. The vulnerability has a CVSS score of 5.4 and is classified as MEDIUM severity. Affec [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-75639

CVE-2026-75639 is a DOM-based Cross-Site Scripting (XSS) vulnerability affecting Adobe Experience Manager. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. This requires user interaction, as a victim must visit a crafted webpage. The vulnerability has a CVSS score of 5.4 and MEDIUM severity. Defenders shoul [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-75637

CVE-2026-75637 is a DOM-based Cross-Site Scripting (XSS) vulnerability affecting Adobe Experience Manager. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation requires user interaction, as a victim must visit a crafted webpage. The vulnerability has a CVSS score of 5.4 and is classified as MEDIUM [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-75636

CVE-2026-75636 is a DOM-based Cross-Site Scripting (XSS) vulnerability affecting Adobe Experience Manager. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. This requires user interaction, as a victim must visit a crafted webpage. The vulnerability has a medium severity and requires defenders to verify and a [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-75635

CVE-2026-75635 is a DOM-based Cross-Site Scripting (XSS) vulnerability affecting Adobe Experience Manager. Exploitation requires user interaction, as a victim must visit a crafted webpage. The vulnerability has a CVSS score of 5.4 and is classified as MEDIUM severity. Defenders should assess exposure and prioritize patching, particularly for versions prior to 6.5.25.0 or 2026.8.0 for AEM Cloud Service. Th [truncated]

HIGH Adobe CVE published 2026-09-08

CVE-2026-75631

CVE-2026-75631 is a high-severity vulnerability in Adobe Photoshop that could lead to arbitrary code execution. This PatchSiren debrief provides an AI-assisted analysis based on the CVE Program record, NVD vulnerability detail, and a vendor advisory. The vulnerability, an out-of-bounds write issue, requires user interaction to open a malicious file, potentially leading to elevated privileges. Defenders sh [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-75629

CVE-2026-75629 is a DOM-based Cross-Site Scripting (XSS) vulnerability affecting Adobe Experience Manager. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation requires user interaction, as a victim must visit a crafted webpage. This vulnerability has a CVSS score of 5.4 and is classified as MEDIUM [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-72627

CVE-2026-72627 is a DOM-based Cross-Site Scripting (XSS) vulnerability affecting Adobe Experience Manager. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. This requires user interaction, as a victim must visit a crafted webpage. The vulnerability's CVSS score of 5.4 indicates a MEDIUM severity level. Defen [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-72626

CVE-2026-72626 is a DOM-based Cross-Site Scripting (XSS) vulnerability affecting Adobe Experience Manager. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation requires user interaction, as a victim must visit a crafted webpage. This vulnerability has a CVSS score of 5.4 and is classified as MEDIUM [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-71565

CVE-2026-71565 is a DOM-based Cross-Site Scripting (XSS) vulnerability affecting Adobe Experience Manager. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation requires user interaction, as a victim must visit a crafted webpage. This vulnerability has a medium severity and a CVSS score of 5.4. Adob [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-71440

A stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager could allow a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. The vulnerability's scope has been changed. Defenders should prioritize verifying and remediating vulnerable Adobe [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-71388

CVE-2026-71388 is a DOM-based Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. This requires user interaction, as a victim must visit a crafted webpage. The vulnerability has a medium severity and a CVSS score of 5.4. Defenders should ass [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-71357

CVE-2026-71357 is a DOM-based Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. This requires user interaction, as a victim must visit a crafted webpage. The vulnerability's scope is changed, indicating potential impact on other components [truncated]

MEDIUM Adobe CVE published 2026-09-08

CVE-2026-71356

CVE-2026-71356 is a DOM-based Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. This requires user interaction, as a victim must visit a crafted webpage. The vulnerability's scope and affected versions require verification from official Ad [truncated]

CRITICAL Adobe CVE published 2026-09-08

CVE-2026-48273

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-08T20:17:33.560Z and has not been modified since then. The NVD entry is currently Analyzed. CVE-2026-48273 is an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability in Adobe ColdFusion. A low-privileged attacker could exploit this vulnerability to exe [truncated]