vciy

Adobe Experience Manager: 54 records in one advisory

54 records announced together, published 2026-06-09, every one of them citing the same advisory.

The advisory

Every record in this batch cites https://helpx.adobe.com/security/products/experience-manager/apsb26-56.html. That is the CNA's own reference, held in the index, and it is why these records are on one page.

What the records offer

All 54 records publish a fixed version.

No record in this batch is listed by CISA in held sources.

Held sources describe every record in this batch identically. Nothing but the identifier and the publication time separates one from another here.

Most commonly mapped weakness across the batch: CWE-79 Cross-site Scripting (Stored XSS)…

What this page does not cover

This batch is 54 of the 57 records that cite the same advisory. The other 3 are different findings announced alongside it.

None of those 3 is grouped with any other. Each one has its own record page and nothing else.

The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.

What this batch was researched, not held

Fifty-six of this bulletin's 57 identifiers carry a name, and the one that does not is the only open redirect

APSB26-56 is Adobe's Experience Manager bulletin of 9 June 2026, rated priority 3, covering Experience Manager as a Cloud Service, 6.5 LTS Service Pack 1 and earlier and 6.5 Service Pack 24 and earlier, with fixes in Cloud Service release 2026.05, 6.5 LTS Service Pack 2 and 6.5 Service Pack 25. Fifty-seven public records point at it, all published on the day of the bulletin, and they are nearly all one thing: 54 are cross-site scripting, 2 are improper input validation and 1 is an open redirect. The acknowledgements are just as lopsided. Adobe credits a handle written green-jam with 40 identifiers, a handle written anonymous_blackzero with 13, a handle written lpi with 2, and a single identifier, CVE-2026-47990, to Marco Ventura, Claudia Bartolini and Massimiliano Brolli of the TIM Security Red Team Research group at TIM S.p.A. That is 56 credited identifiers from four lines, with two handles accounting for 53 of them. Line them up against the 57 records and one identifier is credited to nobody: CVE-2026-47991. It is also the only open redirect in the set.

These were announced on one day by one vendor and mostly reported by two people, but each names a separate injection point in a separate part of Experience Manager. The fix for the one you are reading does not cover the others, and a credit line shared with 39 other identifiers is not evidence that they are the same bug.

2026-06-09Adobe publishes APSB26-56 at priority 3, and all 57 public records pointing at it are published the same day.

Adobe names no component, no screen and no parameter for any entry, and publishes no reproduction, so this cannot tell you where in Experience Manager any of these sits. Unlike some vendors who map each identifier to a path, Adobe leaves you with a weakness class and a severity. It also gives no report dates, so the time between finding and announcement is unknown, and the handles green-jam, anonymous_blackzero and lpi are the only identification Adobe offers for 55 of the 56 credits.

Written from adobe.com, helpx.adobe.com, services.nvd.nist.gov. Reviewed for whether every claim traces to one of them, by two independent graders, citation support 4.44 of 5, uniqueness 4 of 5. Stated at high confidence. Nothing in this box is a value the index holds, and none of it opens a receipt.

Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.

CVE-2026-34692Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CVE-2026-47935Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CVE-2026-47936Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-47939Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-47941Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-47942Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-47943Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-47944Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-47945Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-47946Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CVE-2026-47947Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CVE-2026-47948Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-47949Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-47950Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-47951Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-47953Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-47954Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-47956Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-47957Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-47958Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-47962Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-47966Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-47970Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-47972Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-47973Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-47974Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-47975Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-47977Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-47978Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-47980Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-47981Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-47982Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CVE-2026-47983Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CVE-2026-47985Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CVE-2026-47986Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CVE-2026-47987Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CVE-2026-47989Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CVE-2026-47990Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-47993Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CVE-2026-48250Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CVE-2026-48251Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CVE-2026-48256Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CVE-2026-48258Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CVE-2026-48264Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CVE-2026-48265Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CVE-2026-48266Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CVE-2026-48268Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CVE-2026-48271Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CVE-2026-48280Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
CVE-2026-48297Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-48299Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-48300Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-48301Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-48304Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

54 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.