Exposure of Adobe Experience Manager

CMS
219
exposure score
18,203
sites use
1
exploited
4
critical
Vexday analysis

Com 1.022 CVEs catalogadas, o Adobe Experience Manager acumula um histórico de vulnerabilidades considerável, ainda que sua taxa de exploração ativa esteja abaixo da média geral do catálogo CISA KEV. A falha mais comum é CWE-79 (Cross-Site Scripting), o que indica exposição persistente a vetores de injeção de script no lado do cliente — um padrão relevante em plataformas de gerenciamento de conteúdo com amplas superfícies de entrada. Atenção especial deve ser dada ao CVE-2025-54253, atualmente a vulnerabilidade mais crítica em exploração ativa, com índice EPSS de aproximadamente 0,90, sinalizando altíssima probabilidade de exploração real e exigindo priorização imediata de mitigação. O volume de 61 CVEs surgidas nos últimos 90 dias reforça que a superfície de ataque da plataforma segue em expansão ativa, demandando monitoramento contínuo e ciclos de patching ágeis.

CVEs

1,022 results
CVE-2026-47950MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.2%CVE-2026-47944MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.2%CVE-2026-47990MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.2%CVE-2026-47981MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.2%CVE-2025-64551MEDIUMAdobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)EPSS 0.2%CVE-2026-47980MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.2%CVE-2026-47978MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.2%CVE-2026-47977MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.2%CVE-2026-47975MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.2%CVE-2026-47974MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.2%CVE-2026-47972MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.2%CVE-2026-47949MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.2%CVE-2026-47966MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.2%CVE-2026-47962MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.2%CVE-2026-47958MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.2%CVE-2026-47957MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.2%CVE-2026-47973MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.2%CVE-2026-27226MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.2%CVE-2025-64566MEDIUMAdobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)EPSS 0.2%CVE-2025-64569MEDIUMAdobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)EPSS 0.2%

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →