Adobe Experience Manager: 72 records in one advisory
72 records announced together, published 2026-09-08, every one of them citing the same advisory.
The advisory
Every record in this batch cites https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html. That is the CNA's own reference, held in the index, and it is why these records are on one page.
What the records offer
All 72 records publish a fixed version.
No record in this batch is listed by CISA in held sources.
Held sources describe every record in this batch identically. Nothing but the identifier and the publication time separates one from another here.
Most commonly mapped weakness across the batch: CWE-79 Cross-site Scripting (DOM-based XSS)…
What tells these apart
Nothing held does. One advisory announced every record here on the same day, under the same title or none, against the same product, and the index holds no distinguishing value for any of them. The rows below are listed by identifier for that reason. That is the state of the sources, not a gap in this page.
What this page does not cover
This batch is 72 of the 107 records that cite the same advisory. The other 35 are different findings announced alongside it.
33 of them are on the sibling batch linked below. The remaining 2 are grouped with nothing and have only their own record pages.
Other batches under the same advisory: adobe-apsb26-98-2bd4c7265c
The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.
What this batch was researched, not held
Adobe's biggest September 2026 advisory, and the half of it that needs a victim to click
Trend Micro's Zero Day Initiative reviewed Adobe's September 2026 releases and recorded this Experience Manager bulletin as the month's largest, at 107 identifiers, with a deployment priority rating of 2. It also counted 22 of Adobe's identifiers that month as arriving through its own programme. The records in this group are the ones that describe a different kind of scripting flaw from the rest of the bulletin. CVE-2025-64542 is the example to read: the attacker manipulates what the browser has already loaded rather than storing anything on the server, so the record says exploitation requires a victim to visit a crafted webpage. The same record adds the phrase "Scope is changed", which is Adobe saying the script escapes the boundary it was supposed to stay inside, and it scores 5.4. The bulletin covers Experience Manager as a Cloud Service up to release 2026.7.0, Experience Manager 6.5 LTS up to Service Pack 2, and Experience Manager 6.5 up to Service Pack 24.
The cloud records in this bulletin state an affected release but no build number you can read off a running system, so there is nothing in them to compare against what you have. The one useful line for triage is the requirement in the description itself: someone has to visit a crafted page before anything happens. The other records announced on the same day are separate entries.
The description tells you the browser is the stage and does not tell you which page. It names no script, no parameter and no component, so you cannot work out which crafted page a visitor would have to reach. Nothing in the record says whether the crafted page has to be on your own site or somewhere else.
Written from zerodayinitiative.com, cveawg.mitre.org, cisecurity.org. Reviewed for whether every claim traces to one of them, by two independent graders, citation support 4.44 of 5, uniqueness 4 of 5. Stated at high confidence. Nothing in this box is a value the index holds, and none of it opens a receipt.
Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.
72 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.