NCSC-2026-0246 [1.00] [M/H] Vulnerabilities fixed in Adobe Experience Manager
Adobe has fixed multiple vulnerabilities in Adobe Experience Manager. The vulnerabilities in Adobe Experience Manager include, among others, the lack of authentication on a critical function, allowing unauthorized write actions without user interaction. Additionally, there is a Server-Side Request Forgery (SSRF) vulnerability that allows an attacker with low privileges to execute arbitrary code on the server and gain access to accounts or sessions. Furthermore, there are multiple Cross-Site Scripting (XSS) vulnerabilities, both stored and DOM-based, that allow attackers to inject and execute malicious JavaScript code in users' browsers, potentially leading to session hijacking and unauthorized actions. There is also a Path Traversal vulnerability that allows reading files outside the intended directory structure without user interaction. Additionally, there is an XML External Entity (XXE) vulnerability that allows the execution of arbitrary code, access to sensitive files, and privilege escalation without user interaction. These vulnerabilities affect the confidentiality, integrity, and availability of systems running Adobe Experience Manager.
CSIRTS triage
- What
- Multiple vulnerabilities allow unauthorized actions and access to sensitive data.
- Who is affected
- Users of Adobe Experience Manager.
- Urgency
- Remediation is critical due to the potential for exploitation and data breaches.
- Action
- Users should update to the latest version of Adobe Experience Manager.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Adobe Experience Manager
Get an email when a new Adobe Experience Manager advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0246
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-482520.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all scored CVEs.
- Low exploitation riskCVE-2026-482590.68% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 49% of all scored CVEs.
- Low exploitation riskCVE-2026-482630.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all scored CVEs.
- Low exploitation riskCVE-2026-483100.51% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all scored CVEs.
- Low exploitation riskCVE-2026-483550.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all scored CVEs.
- Moderate exploitation riskCVE-2026-483591.7% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 75% of all scored CVEs.
- Low exploitation riskCVE-2026-482530.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all scored CVEs.
- Low exploitation riskCVE-2026-482540.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all scored CVEs.
- Low exploitation riskCVE-2026-482550.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all scored CVEs.
- Low exploitation riskCVE-2026-482570.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-48252 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48259 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48263 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48310 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48355 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48359 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48253 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48254 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48255 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48257 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48260 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48261 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48262 | coverage & exploitation status | NVD · CVE.org |
| CVE-2023-25690 | coverage & exploitation status | NVD · CVE.org |
| CVE-2025-64538 | coverage & exploitation status | NVD · CVE.org |
| CVE-2025-64537 | coverage & exploitation status | NVD · CVE.org |
| CVE-2025-64539 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [high] Apache HTTP Server: Multiple vulnerabilities allow HTTP response splittingcert-bund
- high[NEW] [high] Adobe Experience Manager: Multiple vulnerabilitiescert-bund
- criticalCVE-2026-48359: Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Referen…nvd
- mediumCVE-2026-48355: Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that…nvd
- highCVE-2026-48310: Adobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restricted D…nvd
- mediumCVE-2026-48263: Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that…nvd
- mediumCVE-2026-48262: Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. …nvd
- mediumCVE-2026-48261: Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. …nvd
- mediumCVE-2026-48260: Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. …nvd
- criticalCVE-2026-48259: Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability tha…nvd
- mediumCVE-2026-48257: Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. …nvd
- mediumCVE-2026-48255: Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. …nvd
Recent advisories for Adobe Experience Manager
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEW] [high] Adobe Experience Manager: Multiple vulnerabilitiescert-bund · 2026-07-15
- criticalCVE-2026-48359: Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Referen…nvd · 2026-07-14
- mediumCVE-2026-48355: Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that…nvd · 2026-07-14
- highCVE-2026-48310: Adobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restricted D…nvd · 2026-07-14
- mediumCVE-2026-48263: Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that…nvd · 2026-07-14
- mediumCVE-2026-48262: Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. …nvd · 2026-07-14
More from NCSC-NL Advisories
- unknownNCSC-2026-0274 [1.00] [M/H] Kwetsbaarheid verholpen in SolarWinds Web Help Desk2026-07-31
- unknownNCSC-2026-0273 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic2026-07-31
- unknownNCSC-2026-0272 [1.00] [M/H] Kwetsbaarheden verholpen in JFrog Artifactory2026-07-31
- unknownNCSC-2026-0271 [1.00] [M/H] Vulnerability fixed in Cisco Secure Firewall Management Center2026-07-30
- unknownNCSC-2026-0270 [1.00] [M/M] Vulnerabilities fixed in GitLab by GitLab Inc.2026-07-30