VDB

CVE-2026-48359

CVE-2026-48359 PUBLISHED CVSS 9.600000381469727 CRITICAL

Adobe has released updates for Adobe Experience Manager (AEM). This update resolves vulnerabilities rated important. Successful exploitation of these vulnerabilities could result in arbitrary code execution, security feature bypass, arbitrary file system read, and privilege escalation. Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates. Vulnerability: Improper Restriction of XML External Entity Reference ('XXE') (CWE-611) Impact: Arbitrary code execution Severity: Critical CVSS: 9.6 CWE: CWE-611

EPSS 1.70% · 75.1th percentile

Risk Scores

CVSS 3.1
9.600000381469727
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
EPSS Score
1.70%
75.1th percentile

Timeline

  • Jul 14, 2026 CVE Published
  • Jul 15, 2026 Coalition ESS Score
  • Jul 17, 2026 CVE Updated
  • Aug 7, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›