vciy

Adobe Experience Manager: 33 records in one advisory

33 records announced together, published between 2026-04-14 and 2026-09-08, every one of them citing the same advisory.

The advisory

Every record in this batch cites https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html. That is the CNA's own reference, held in the index, and it is why these records are on one page.

What the records offer

All 33 records publish a fixed version.

No record in this batch is listed by CISA in held sources.

Held sources describe every record in this batch identically. Nothing but the identifier and the publication time separates one from another here.

Most commonly mapped weakness across the batch: CWE-79 Cross-site Scripting (Stored XSS)…

What this page does not cover

This batch is 33 of the 107 records that cite the same advisory. The other 74 are different findings announced alongside it.

72 of them are on the sibling batch linked below. The remaining 2 are grouped with nothing and have only their own record pages.

Other batches under the same advisory: adobe-apsb26-98-e871ebd408

The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.

What this batch was researched, not held

Reported in November 2025, published in September 2026

Every record in this group waited about ten months between the day its identifier was reserved and the day Adobe published it. CVE-2025-64618 and CVE-2025-64584 were both reserved on 5 November 2025 and both published on 8 September 2026. CVE-2025-64830 was reserved six days later, on 11 November 2025, and published on the same September day. All three carry the same description: a stored cross-site scripting flaw that a low-privileged attacker can use to put a script into a form field, which then runs in the browser of whoever views the page. Adobe's own severity vector on CVE-2025-64830 is CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N and scores 5.4, and the two parts worth reading are PR:L and UI:R. PR:L means the attacker already needs an account on the system. UI:R means nothing happens until some other person opens the page. These records name Experience Manager as a Cloud Service up to release 2026.7.0, Experience Manager 6.5 LTS up to Service Pack 2, and Experience Manager 6.5 up to 6.5.24, and each names its own fixed release of 2026.8.0, Service Pack 3 and 6.5.25.

The publication date on this record is not the date anyone found the problem. The identifier was reserved about ten months earlier, so treat the September 2026 date as the day Adobe chose to say it out loud. The other records announced with it are separate entries that happen to share a description, and the fix named in this record is the one named in this record.

2025-11-05Adobe reserves the identifiers CVE-2025-64618 and CVE-2025-64584
2025-11-11Adobe reserves CVE-2025-64830, six days after the others
2026-09-08All three records are published, ten months after reservation
2026-09-09Adobe updates the records the day after publishing them

The record says an attacker needs a low-privileged account, and then does not say which account. It names no role, no component and no form field, so there is nothing here to check your own author instance against. The reservation date tells you the report is older than the publication date, and nothing published says how much older, because Adobe does not give a report date.

Written from cveawg.mitre.org, cveawg.mitre.org, cveawg.mitre.org, cisecurity.org. Reviewed for whether every claim traces to one of them, by two independent graders, citation support 4.44 of 5, uniqueness 4 of 5. Stated at high confidence. Nothing in this box is a value the index holds, and none of it opens a receipt.

Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.

CVE-2025-64584Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2025-64588Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2025-64589Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2025-64610Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2025-64618Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2025-64830Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2025-64838Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2025-64854Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2025-64866Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2025-64868Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-27222Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-27227Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-27238InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
CVE-2026-27258Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-71440Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-75642Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-75643Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-75644Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-75727Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-75729Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-75730Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-75731Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-75733Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-75734Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-75735Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-75736Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-75737Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-75738Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-75739Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-75740Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-75741Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-75742Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-79905Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

33 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.