Adobe Experience Manager: 33 records in one advisory
33 records announced together, published between 2026-04-14 and 2026-09-08, every one of them citing the same advisory.
The advisory
Every record in this batch cites https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html. That is the CNA's own reference, held in the index, and it is why these records are on one page.
What the records offer
All 33 records publish a fixed version.
No record in this batch is listed by CISA in held sources.
Held sources describe every record in this batch identically. Nothing but the identifier and the publication time separates one from another here.
Most commonly mapped weakness across the batch: CWE-79 Cross-site Scripting (Stored XSS)…
What this page does not cover
This batch is 33 of the 107 records that cite the same advisory. The other 74 are different findings announced alongside it.
72 of them are on the sibling batch linked below. The remaining 2 are grouped with nothing and have only their own record pages.
Other batches under the same advisory: adobe-apsb26-98-e871ebd408
The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.
What this batch was researched, not held
Reported in November 2025, published in September 2026
Every record in this group waited about ten months between the day its identifier was reserved and the day Adobe published it. CVE-2025-64618 and CVE-2025-64584 were both reserved on 5 November 2025 and both published on 8 September 2026. CVE-2025-64830 was reserved six days later, on 11 November 2025, and published on the same September day. All three carry the same description: a stored cross-site scripting flaw that a low-privileged attacker can use to put a script into a form field, which then runs in the browser of whoever views the page. Adobe's own severity vector on CVE-2025-64830 is CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N and scores 5.4, and the two parts worth reading are PR:L and UI:R. PR:L means the attacker already needs an account on the system. UI:R means nothing happens until some other person opens the page. These records name Experience Manager as a Cloud Service up to release 2026.7.0, Experience Manager 6.5 LTS up to Service Pack 2, and Experience Manager 6.5 up to 6.5.24, and each names its own fixed release of 2026.8.0, Service Pack 3 and 6.5.25.
The publication date on this record is not the date anyone found the problem. The identifier was reserved about ten months earlier, so treat the September 2026 date as the day Adobe chose to say it out loud. The other records announced with it are separate entries that happen to share a description, and the fix named in this record is the one named in this record.
The record says an attacker needs a low-privileged account, and then does not say which account. It names no role, no component and no form field, so there is nothing here to check your own author instance against. The reservation date tells you the report is older than the publication date, and nothing published says how much older, because Adobe does not give a report date.
Written from cveawg.mitre.org, cveawg.mitre.org, cveawg.mitre.org, cisecurity.org. Reviewed for whether every claim traces to one of them, by two independent graders, citation support 4.44 of 5, uniqueness 4 of 5. Stated at high confidence. Nothing in this box is a value the index holds, and none of it opens a receipt.
Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.
33 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.