CVE-2026-75744

HIGH

Adobe Experience Manager Forms JEE is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable fo...

CVSS 3.18.1
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, high privileges required, requires user interaction, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, no availability impact.
CWE Weakness Definitions
CWE-79: Cross-Site Scripting (XSS)

Attacker injects malicious scripts into web pages viewed by other users, executing in the victim's browser context.

Related Attack Patterns (CAPEC)
CAPEC-85 AJAX Footprinting
via CWE-79
CAPEC-209 XSS Using MIME Type Mismatch
via CWE-79
CAPEC-588 DOM-Based XSS
via CWE-79
CAPEC-591 Reflected XSS
via CWE-79
CAPEC-592 Stored XSS
via CWE-79
Show all 6
via CWE-79

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A high severity vulnerability (CVE-2026-75744) affects the target system. Adobe Experience Manager Forms JEE is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a ...

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-75744?
A high severity vulnerability (CVE-2026-75744) affects the target system. Adobe Experience Manager Forms JEE is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a ...
What is the CVSS score for CVE-2026-75744?
CVE-2026-75744 has CVSS 8.1 (High). Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N.
Is CVE-2026-75744 actively exploited?
No confirmed active exploitation of CVE-2026-75744 as of 2026-09-23.
How do I remediate CVE-2026-75744?
Apply vendor patches for CVE-2026-75744. Monitor the vendor advisories.
Vulnerability Details
CVE IDCVE-2026-75744
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N
Published2026-09-22
Last Modified2026-09-22
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

Adobe Experience Manager Forms JEE is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.

Source: NIST NVD / MITRE CVE Database

Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: September 2026 | Threat Age: 0 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →