EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

NCSC-2026-0390 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Experience Manager Forms JEE

Official source
EudorIA operational summary

What it means

Priority 70/100

Adobe ha rimosso 6 vulnerabilità in Adobe Experience Manager Forms JEE, tra cui AEM 6.5 Forms e AEM 6.5 LTS Forms. Le vulnerabilità includono autorizzazione errata, validazione insufficiente, SSRF, XSS e CSRF. Alcune sono critiche e possono essere sfruttate senza autenticazione. CVE-2026-75745 ha un CVSS di 9,8 e può essere sfruttata senza autenticazione e interazione utente per eseguire codice arbitrario. Adobe non segnala attacchi attivi in corso.

Why it matters

Le vulnerabilità critiche in Adobe Experience Manager Forms JEE possono portare a esecuzione di codice arbitrario, escalation di privilegi e bypass di misure di sicurezza. Per le PMI italiane, un attacco potrebbe compromettere dati sensibili e operatività aziendale.

Potential operational benefits

  • Riduzione della superficie esposta alle vulnerabilità
  • Miglioramento della protezione contro attacchi remoti non autorizzati
  • Rilevamento tempestivo di comportamenti sospetti e mitigazione dei rischi
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsPatch managementFirewall NGFW / IPSMonitoraggio / SIEMEDR / XDRMFA / Identità
AudienceITSOCCISO
Information centre

Translation in progress

NCSC Nederland

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

Adobe heeft 6 kwetsbaarheden verholpen in Adobe Experience Manager (AEM) Forms op Java Enterprise Edition (JEE), waaronder AEM 6.5 Forms en AEM 6.5 LTS Forms. De kwetsbaarheden betreffen verschillende beveiligingsproblemen, waaronder onjuiste autorisatie, onvoldoende invoervalidatie, Server-Side Request Forgery (SSRF), Cross-Site Scripting (XSS) en Cross-Site Request Forgery (CSRF). Alle zes kwetsbaarheden zijn als kritiek aangemerkt en twee kunnen zonder authenticatie op afstand worden misbruikt. Succesvol misbruik kan onder meer leiden tot het uitvoeren van willekeurige code, privilege-escalatie en het omzeilen van beveiligingsmaatregelen. CVE-2026-75745 heeft met een CVSS-score van 9,8 de hoogste score en kan zonder authenticatie en gebruikersinteractie op afstand worden misbruikt voor het uitvoeren van willekeurige code. Adobe meldt niet op de hoogte te zijn van actief misbruik.

Source
NCSC Nederland (Paesi Bassi)
Publishing entity
NCSC Nederland
Entity type
National CSIRT
Area
Europe · NL
Original language
nl · translation in preparation
Publication
23/09/2026 15:28
MITRE ATT&CK
T1562
CVE
CVE-2026-75745
Stated country
NL
Technical scope

Affected products and versions

Verification in progress
Information not yet acquired.

The collector will check NVD and the available official vendor advisories.

Open the original source