Référence du bulletin
Mises à jour de sécurité disponibles pour Adobe Experience Manager | APSB26-74
|
|
Date de publication |
Priorité |
|---|---|---|
|
APSB26-74 |
14 juillet 2026 |
3 |
Récapitulatif
Adobe a publié des mises à jour pour Adobe Experience Manager (AEM). Cette mise à jour corrige des vulnérabilités jugées importantes. L’exploitation réussie de ces vulnérabilités pourrait entraîner une exécution de code arbitraire, la lecture de fichier système arbitraire et le contournement des fonctions de sécurité, ainsi qu'une escalade des privilèges.
Adobe n’a pas connaissance d’exploitations dans la nature des problèmes traités dans ces mises à jour.
Versions concernées
Produit |
Version |
Plate-forme |
|---|---|---|
| Adobe Experience Manager (AEM) |
AEM Cloud Service (CS) Versions 2026.5.0 et antérieures | Toutes |
| Adobe Experience Manager (AEM) | 6.5 LTS Pack de services 2 et antérieurs | Toutes |
| Adobe Experience Manager (AEM) | Pack de services 6.5 25 et versions antérieures | Toutes |
Solution
Adobe attribue à ces mises à jour les priorités suivantes et recommande aux utilisateurs concernés de mettre à jour leurs installations avec les dernières versions des logiciels :
Produit |
Version |
Plate-forme |
Priorité |
Disponibilité |
|---|---|---|---|---|
| Adobe Experience Manager (AEM) |
AEM Cloud Service (CS) Version 2026.6.0 | Toutes | 3 | Notes de mise à jour |
| Adobe Experience Manager (AEM) | 6.5 LTS Service Pack 2 - Correctif pour NPR-43972 | Toutes | 3 | Notes de mise à jour |
| Adobe Experience Manager (AEM) | 6.5 Service Pack 25 - Correctif pour NPR-43971 | Toutes | 3 | Notes de mise à jour |
CVE-2026-48252, CVE-2026-48259, CVE-2026-48263, CVE-2026-48310, CVE-2026-48355 affectent uniquement les versions AEMaaCS indiquées.
Détails concernant la vulnérabilité
| Vulnerability Category |
Vulnerability Impact |
Severity |
CVSS base score |
CVSS vector |
CVE Number |
| Server-Side Request Forgery (SSRF) (CWE-918) | Arbitrary code execution | Critical | 9.6 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N | CVE-2026-48259 |
| Improper Restriction of XML External Entity Reference ('XXE') (CWE-611) | Arbitrary code execution | Critical | 9.6 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N | CVE-2026-48359 |
| Missing Authentication for Critical Function (CWE-306) | Security feature bypass | Critical | 8.6 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N | CVE-2026-48252 |
| Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) | Arbitrary file system read | Critical | 8.6 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N | CVE-2026-48310 |
| Cross-site Scripting (Stored XSS) (CWE-79) | Arbitrary code execution | Important | 5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | CVE-2026-48263 |
| Cross-site Scripting (DOM-based XSS) (CWE-79) | Arbitrary code execution | Important | 5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | CVE-2026-48253 |
| Cross-site Scripting (Stored XSS) (CWE-79) | Arbitrary code execution | Important | 5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | CVE-2026-48355 |
| Cross-site Scripting (DOM-based XSS) (CWE-79) | Arbitrary code execution | Important | 5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | CVE-2026-48254 |
| Cross-site Scripting (DOM-based XSS) (CWE-79) | Arbitrary code execution | Important | 5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | CVE-2026-48255 |
| Cross-site Scripting (DOM-based XSS) (CWE-79) | Arbitrary code execution | Important | 5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | CVE-2026-48257 |
| Cross-site Scripting (DOM-based XSS) (CWE-79) | Arbitrary code execution | Important | 5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | CVE-2026-48260 |
| Cross-site Scripting (DOM-based XSS) (CWE-79) | Arbitrary code execution | Important | 5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | CVE-2026-48261 |
| Cross-site Scripting (DOM-based XSS) (CWE-79) | Privilege escalation | Important | 5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | CVE-2026-48262 |
If a customer is using Apache httpd in a proxy with a non-default configuration, they may be impacted by CVE-2023-25690 - please read more here: https://httpd.apache.org/security/vulnerabilities_24.html
Acknowledgments
Adobe would like to thank the following for reporting these issues and for working with Adobe to help protect our customers:
- green-jam - CVE-2026-48253, CVE-2026-48254, CVE-2026-48255, CVE-2026-48257, CVE-2026-48260, CVE-2026-48261, CVE-2026-48262
- Dylan Pindur, Adam Kues, and Patrik Grobshäuser of Assetnote - CVE-2026-48252, CVE-2026-48259, CVE-2026-48263, CVE-2026-48310, CVE-2026-48355, CVE-2026-48359
NOTE: Adobe has a public bug bounty program with HackerOne. If you are interested in working with Adobe as an external security researcher, please check out https://hackerone.com/adobe
Revisions
December 18, 2025: Added CVE-2025-64538
December 10, 2025: Removed CVE-2025-64540
December 24, 2025: Added note - "AEM 6.5 and LTS versions are not impacted by the following CVEs: CVE-2025-64537, CVE-2025-64538, CVE-2025-64539."
Pour plus d’informations, visitez https://helpx.adobe.com/fr/security.html ou envoyez un e-mail à PSIRT@adobe.com.
Recevez de l’aide plus rapidement et plus facilement
Nouvel utilisateur ?