Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4501 articles · 223832 vulns · 37/41 feeds (7d)
← Back to list
9.6
CVE-2026-82000PATCHED
adobe · aem 6.5 forms jee

Adobe Experience Manager Forms JEE | Server-Side Request Forgery (SSRF) (CWE-918)

Description

Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope is changed.

Affected Products

VendorProductVersions
adobeaem 6.5 forms jee0, 0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
adobeexperience manager formscert_advisory90%

References

  • https://helpx.adobe.com/security/products/aem-forms/apsb26-151.html(vendor-advisory)

Related News (3 articles)

Tier D
SecurityWeek4d ago
Adobe Patches Critical Flaws in Connect, AEM Forms
→ No new info (linked only)
Tier B
BSI Advisories4d ago
[NEU] [hoch] Adobe Experience Manager Forms: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB5d ago
CVE-2026-82000 | Adobe Experience Manager Forms JEE 6.5 server-side request forgery
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.6 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
6.5.25 (AEMForms-6.5.0-0134 Hotfix)6.5 LTS SP3
CWECWE-918
PublishedSep 22, 2026
Trending Score30
Source articles3
Independent3
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-71362EXPKEV
Adobe Commerce | Incorrect Authorization (CWE-863)
Trending: 111
CRITICALCVE-2026-75745
Adobe Experience Manager Forms JEE | Incorrect Authorization (CWE-863)
Trending: 36
CRITICALCVE-2026-75682
Adobe Connect | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Trending: 30
CRITICALCVE-2026-75698
Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79)
Trending: 30
HIGHCVE-2026-34689
Adobe Connect | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Trending: 28

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 22, 2026
Discovered by ZDM
Sep 22, 2026
Patch Available
Sep 23, 2026