Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4505 articles · 223849 vulns · 37/41 feeds (7d)
← Back to list
10.0
CVE-2026-75745PATCHED
adobe · aem 6.5 forms jee

Adobe Experience Manager Forms JEE | Incorrect Authorization (CWE-863)

Description

Adobe Experience Manager Forms JEE is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

Affected Products

VendorProductVersions
adobeaem 6.5 forms jee0, 0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
adobeexperience manager formscert_advisory90%

References

  • https://helpx.adobe.com/security/products/aem-forms/apsb26-151.html(vendor-advisory)

Related News (3 articles)

Tier B
BSI Advisories4d ago
[NEU] [hoch] Adobe Experience Manager Forms: Mehrere Schwachstellen
→ No new info (linked only)
Tier D
Heise Security4d ago
Patchday: Adobe Connect ist unter Android, macOS und Windows verwundbar
→ No new info (linked only)
Tier C
VulDB5d ago
CVE-2026-75745 | Adobe Experience Manager Forms JEE improper authorization
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.110.0 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
6.5.25 (AEMForms-6.5.0-0134 Hotfix)6.5 LTS SP3
CWECWE-863
PublishedSep 22, 2026
Trending Score36
Source articles3
Independent3
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-71362EXPKEV
Adobe Commerce | Incorrect Authorization (CWE-863)
Trending: 109
CRITICALCVE-2026-75682
Adobe Connect | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Trending: 29
CRITICALCVE-2026-82000
Adobe Experience Manager Forms JEE | Server-Side Request Forgery (SSRF) (CWE-918)
Trending: 29
CRITICALCVE-2026-75698
Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79)
Trending: 29
HIGHCVE-2026-34689
Adobe Connect | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Trending: 28

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 22, 2026
Discovered by ZDM
Sep 22, 2026
Patch Available
Sep 26, 2026