Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2984 articles · 161878 vulns · 36/41 feeds (7d)
← Back to list
3.5
CVE-2026-48289EXPLOITEDPATCHED
adobe · adobe experience manager

Adobe Experience Manager | Improper Input Validation (CWE-20)

Description

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.

Affected Products

VendorProductVersions
adobeadobe experience manager0

References

  • https://helpx.adobe.com/security/products/experience-manager/apsb26-56.html(vendor-advisory)

Related News (1 articles)

Tier C
VulDB3h ago
CVE-2026-48289 | Adobe Experience Manager up to 2026.04 improper authorization (apsb26-56)
→ No new info (linked only)
CVSS 3.13.5 LOW
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
https://helpx.adobe.com/security/products/experience-manager/apsb26-56.html
CWECWE-20
PublishedJun 9, 2026
Last enriched3h agov2
Trending Score41
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-34700EXP
InDesign Desktop | Out-of-bounds Write (CWE-787)
Trending: 51
HIGHCVE-2026-34697EXP
InDesign Desktop | Stack-based Buffer Overflow (CWE-121)
Trending: 51
HIGHCVE-2026-34699EXP
InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
Trending: 51
HIGHCVE-2026-34698EXP
InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
Trending: 51
HIGHCVE-2026-48293EXP
InDesign Desktop | Out-of-bounds Write (CWE-787)
Trending: 51

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 9, 2026
Discovered by ZDM
Jun 9, 2026
Updated: description, severity, cweIds, activelyExploited
Jun 9, 2026
Actively Exploited
Jun 9, 2026
Patch Available
Jun 9, 2026

Version History

v2
Last enriched 3h ago
v2Tier C3h ago

Updated severity to CRITICAL, added CVE-2026-48289, and changed exploit availability to false.

descriptionseveritycweIdsactivelyExploited
via VulDB
v14h ago

Initial creation