Adobe Experience Manager: 54 records in one advisory
54 records announced together, published 2026-06-09, every one of them citing the same advisory.
The advisory
Every record in this batch cites https://helpx.adobe.com/security/products/experience-manager/apsb26-56.html. That is the CNA's own reference, held in the index, and it is why these records are on one page.
What the records offer
All 54 records publish a fixed version.
No record in this batch is listed by CISA in held sources.
Held sources describe every record in this batch identically. Nothing but the identifier and the publication time separates one from another here.
Most commonly mapped weakness across the batch: CWE-79 Cross-site Scripting (Stored XSS)…
What this page does not cover
This batch is 54 of the 57 records that cite the same advisory. The other 3 are different findings announced alongside it.
None of those 3 is grouped with any other. Each one has its own record page and nothing else.
The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.
What this batch was researched, not held
Fifty-six of this bulletin's 57 identifiers carry a name, and the one that does not is the only open redirect
APSB26-56 is Adobe's Experience Manager bulletin of 9 June 2026, rated priority 3, covering Experience Manager as a Cloud Service, 6.5 LTS Service Pack 1 and earlier and 6.5 Service Pack 24 and earlier, with fixes in Cloud Service release 2026.05, 6.5 LTS Service Pack 2 and 6.5 Service Pack 25. Fifty-seven public records point at it, all published on the day of the bulletin, and they are nearly all one thing: 54 are cross-site scripting, 2 are improper input validation and 1 is an open redirect. The acknowledgements are just as lopsided. Adobe credits a handle written green-jam with 40 identifiers, a handle written anonymous_blackzero with 13, a handle written lpi with 2, and a single identifier, CVE-2026-47990, to Marco Ventura, Claudia Bartolini and Massimiliano Brolli of the TIM Security Red Team Research group at TIM S.p.A. That is 56 credited identifiers from four lines, with two handles accounting for 53 of them. Line them up against the 57 records and one identifier is credited to nobody: CVE-2026-47991. It is also the only open redirect in the set.
These were announced on one day by one vendor and mostly reported by two people, but each names a separate injection point in a separate part of Experience Manager. The fix for the one you are reading does not cover the others, and a credit line shared with 39 other identifiers is not evidence that they are the same bug.
Adobe names no component, no screen and no parameter for any entry, and publishes no reproduction, so this cannot tell you where in Experience Manager any of these sits. Unlike some vendors who map each identifier to a path, Adobe leaves you with a weakness class and a severity. It also gives no report dates, so the time between finding and announcement is unknown, and the handles green-jam, anonymous_blackzero and lpi are the only identification Adobe offers for 55 of the 56 credits.
Written from adobe.com, helpx.adobe.com, services.nvd.nist.gov. Reviewed for whether every claim traces to one of them, by two independent graders, citation support 4.44 of 5, uniqueness 4 of 5. Stated at high confidence. Nothing in this box is a value the index holds, and none of it opens a receipt.
Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.
54 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.