vciy

Adobe Experience Manager: 72 records in one advisory

72 records announced together, published 2026-09-08, every one of them citing the same advisory.

The advisory

Every record in this batch cites https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html. That is the CNA's own reference, held in the index, and it is why these records are on one page.

What the records offer

All 72 records publish a fixed version.

No record in this batch is listed by CISA in held sources.

Held sources describe every record in this batch identically. Nothing but the identifier and the publication time separates one from another here.

Most commonly mapped weakness across the batch: CWE-79 Cross-site Scripting (DOM-based XSS)…

What tells these apart

Nothing held does. One advisory announced every record here on the same day, under the same title or none, against the same product, and the index holds no distinguishing value for any of them. The rows below are listed by identifier for that reason. That is the state of the sources, not a gap in this page.

What this page does not cover

This batch is 72 of the 107 records that cite the same advisory. The other 35 are different findings announced alongside it.

33 of them are on the sibling batch linked below. The remaining 2 are grouped with nothing and have only their own record pages.

Other batches under the same advisory: adobe-apsb26-98-2bd4c7265c

The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.

What this batch was researched, not held

Adobe's biggest September 2026 advisory, and the half of it that needs a victim to click

Trend Micro's Zero Day Initiative reviewed Adobe's September 2026 releases and recorded this Experience Manager bulletin as the month's largest, at 107 identifiers, with a deployment priority rating of 2. It also counted 22 of Adobe's identifiers that month as arriving through its own programme. The records in this group are the ones that describe a different kind of scripting flaw from the rest of the bulletin. CVE-2025-64542 is the example to read: the attacker manipulates what the browser has already loaded rather than storing anything on the server, so the record says exploitation requires a victim to visit a crafted webpage. The same record adds the phrase "Scope is changed", which is Adobe saying the script escapes the boundary it was supposed to stay inside, and it scores 5.4. The bulletin covers Experience Manager as a Cloud Service up to release 2026.7.0, Experience Manager 6.5 LTS up to Service Pack 2, and Experience Manager 6.5 up to Service Pack 24.

The cloud records in this bulletin state an affected release but no build number you can read off a running system, so there is nothing in them to compare against what you have. The one useful line for triage is the requirement in the description itself: someone has to visit a crafted page before anything happens. The other records announced on the same day are separate entries.

2025-11-05CVE-2025-64542 is reserved with Adobe
2026-09-08Adobe publishes the bulletin and the records in this group reach the CVE list
2026-09-08Trend Micro's Zero Day Initiative publishes its September review and records the bulletin at 107 identifiers with a deployment priority of 2

The description tells you the browser is the stage and does not tell you which page. It names no script, no parameter and no component, so you cannot work out which crafted page a visitor would have to reach. Nothing in the record says whether the crafted page has to be on your own site or somewhere else.

Written from zerodayinitiative.com, cveawg.mitre.org, cisecurity.org. Reviewed for whether every claim traces to one of them, by two independent graders, citation support 4.44 of 5, uniqueness 4 of 5. Stated at high confidence. Nothing in this box is a value the index holds, and none of it opens a receipt.

Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.

72 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.