Adobe 安全公告

Adobe Experience Manager (AEM) Screens 的安全更新 | APSB26-34

公告 ID

发布日期

优先级

APSB26-34

2026 年 4 月 14 日

3

摘要

Adobe 发布了 Adobe Experience Manager (AEM) Screens 的更新。 此更新修复了评级为重要的漏洞。 成功利用此漏洞可能会导致任意代码执行和权限升级。

Adobe 尚未收到任何有关这些更新中所述漏洞被人利用的信息。

受影响的产品版本

产品 版本 平台
Adobe Experience Manager (AEM) Screens

6.5 服务包 24 或更早版本 全部
功能包 11.7 或更早版本  

解决方案

Adobe 按照以下优先级将更新分类,并建议用户将其安装的软件更新至最新版本:

產品

版本

平台

优先级

是否可用

Adobe Experience Manager (AEM) Screens
功能包 11.8 全部 3

AEM 6.5 功能包 11.8 发行说明

漏洞详情

Vulnerability Category
Vulnerability Impact
Severity
CVSS base score
CVSS vector
CVE Number
Cross-site Scripting (Stored XSS) (CWE-79) Arbitrary code execution Important 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVE-2026-27288
Cross-site Scripting (DOM-based XSS) (CWE-79) Privilege escalation Important 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVE-2026-34623
Cross-site Scripting (DOM-based XSS) (CWE-79) Arbitrary code execution Important 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVE-2026-34624
Cross-site Scripting (DOM-based XSS) (CWE-79) Arbitrary code execution Important 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVE-2026-34625
注意:

If a customer is using Apache httpd in a proxy with a non-default configuration, they may be impacted by CVE-2023-25690 - please read more here: https://httpd.apache.org/security/vulnerabilities_24.html

Acknowledgments

Adobe would like to thank the following for reporting these issues and for working with Adobe to help protect our customers: 

  • green-jam: CVE-2026-27288, CVE-2026-34623, CVE-2026-34624, CVE-2026-34625

NOTE: Adobe has a public bug bounty program with HackerOne. If you are interested in working with Adobe as an external security researcher, please check out https://hackerone.com/adobe

 

 

Revisions

December 18, 2025: Added CVE-2025-64538 

December 10, 2025: Removed CVE-2025-64540

December 24, 2025: Added note - "AEM 6.5 and LTS versions are not impacted by the following CVEs: CVE-2025-64537, CVE-2025-64538, CVE-2025-64539."


有关更多信息,请访问 https://helpx.adobe.com/cn/security.html,或发送电子邮件至 PSIRT@adobe.com。

Adobe, Inc.

更快、更轻松地获得帮助

新用户?