CVE-2026-75744

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Adobe Experience Manager Forms JEE is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-23: 109-23
Referenced assets1 URL
By indicator
Full discourse1 post
  • Dark Web Intelligence@DailyDarkWeb

    🚨 ADOBE AEM FORMS JEE CRITICAL — UNAUTHENTICATED AUTHORIZATION BYPASS CAN ENABLE RCE Adobe has released APSB26-151 for Experience Manager Forms on JEE, fixing multiple Critical flaws. The lead issue is CVE-2026-75745: Incorrect Authorization allowing unauthenticated remote arbitrary code execution (CVSS 9.8). • Bulletin: APSB26-151 (Priority 2) — published September 22, 2026 • Lead CVE: CVE-2026-75745 — Incorrect Authorization → arbitrary code execution — Critical CVSS 9.8 (AV:N/AC:L/PR:N/UI:N/S:C) • Also Critical: CVE-2026-81995 (Improper Input Validation / RCE, CVSS 9.1), CVE-2026-82000 / CVE-2026-81999 (SSRF privilege escalation), CVE-2026-75744 (Stored XSS / RCE), plus Critical CSRF security-feature bypass (CVSS 7.1) • Affects: AEM 6.5 LTS Forms SP2 and earlier; AEM 6.5 Forms 6.5.25 and earlier • Fix: AEM 6.5 LTS Forms Service Pack 3; AEM 6.5 Forms 6.5.25 hotfix AEMForms-6.5.0-0134 • Exploitation in the wild: Adobe reports none known as of the bulletin; not on CISA KEV ⚠️ Analyst Note: This is the official Adobe PSIRT bulletin APSB26-151. The unauthenticated network-facing authorization flaw (CVE-2026-75745) is the clearest urgent item for internet-exposed AEM Forms JEE deployments. Adobe rates the update Priority 2 and is not aware of active exploitation; still treat Critical unauth RCE-class issues as patch-now for exposed Forms servers. Official: https://helpx.adobe.com/security/products/aem-forms/apsb26-151.html #DDW #DarkWeb #CyberSecurity #ThreatIntelligence #Adobe #AEM #CVE

    000734.4K
    204.8K followersView on X

Explore more