cbcvebase.
CVE-2026-48259
published 2026-07-14

CVE-2026-48259: Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the…

PriorityP268critical9.6CVSS 3.1
AVNACLPRLUINSCCHIHAN
EPSS
0.41%
33.1th percentile
Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could leverage this vulnerability to issue unauthorized server-side requests, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction. Scope is changed.

Affected

8 ranges
VendorProductVersion rangeFixed in
adobeadobe_experience_manager_6.5<= 6.5.25
adobeadobe_experience_manager_6.5_lts<= SP2
adobeadobe_experience_manager_as_a_cloud_service<= 2026.5.0
adobeexperience_manager<= 6.5.25.0
adobeexperience_manager<= 2020.5.0
adobeexperience_manager
adobeexperience_manager
adobeexperience_manager
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.