Adobe 보안 게시판

Adobe Experience Manager에 대한 보안 업데이트 | APSB26-74

게시판 ID

게시 날짜

우선 순위

APSB26-74

2026년 7월 14일

3

요약

Adobe에서 AEM(Adobe Experience Manager) 업데이트를 발표했습니다. 이 업데이트는 중요한 등급의 취약성을 해결합니다. 이러한 취약점을 악용하면 임의 코드 실행, 보안 기능 무시, 임의 파일 시스템 읽기, 권한 에스컬레이션이 발생할 수 있습니다. 

Adobe는 지금까지 이러한 업데이트에서 해결한 문제와 관련된 악용 사례를 전혀 발견하지 못했습니다.

해당하는 제품 버전

제품

버전

플랫폼

AEM(Adobe Experience Manager)
AEM Cloud Service(CS) 릴리스 2026.5.0 및 이전 버전 모두
AEM(Adobe Experience Manager)  6.5 LTS 서비스 팩 2 및 이전 버전 모두 
AEM(Adobe Experience Manager) 6.5 서비스 팩 25 및 이전 버전 모두 

해결 방법

Adobe는 이러한 업데이트를 다음과 같은 우선 순위 등급으로 분류하고 사용자가 최신 버전으로 업데이트할 것을 권장합니다.

제품

버전

플랫폼

우선 순위

사용 가능성

AEM(Adobe Experience Manager)
AEM Cloud Service(CS) 릴리스 2026.6.0 모두 3 릴리스 정보
AEM(Adobe Experience Manager)  6.5 LTS Service Pack 2 - NPR-43972 핫픽스 모두  3 릴리스 정보
AEM(Adobe Experience Manager) 6.5 Service Pack 25 - NPR-43971 핫픽스 모두  3 릴리스 정보
메모

CVE-2026-48252, CVE-2026-48259, CVE-2026-48263, CVE-2026-48310, CVE-2026-48355의 영향 범위는 명시된 AEMaaCS 릴리스로 제한됩니다. 

취약성 세부 정보

Vulnerability Category
Vulnerability Impact
Severity
CVSS base score
CVSS vector
CVE Number
Server-Side Request Forgery (SSRF) (CWE-918) Arbitrary code execution Critical 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N CVE-2026-48259
Improper Restriction of XML External Entity Reference ('XXE') (CWE-611) Arbitrary code execution Critical 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N CVE-2026-48359
Missing Authentication for Critical Function (CWE-306) Security feature bypass Critical 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N CVE-2026-48252
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) Arbitrary file system read Critical 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N CVE-2026-48310
Cross-site Scripting (Stored XSS) (CWE-79) Arbitrary code execution Important 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVE-2026-48263
Cross-site Scripting (DOM-based XSS) (CWE-79) Arbitrary code execution Important 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVE-2026-48253
Cross-site Scripting (Stored XSS) (CWE-79) Arbitrary code execution Important 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVE-2026-48355
Cross-site Scripting (DOM-based XSS) (CWE-79) Arbitrary code execution Important 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVE-2026-48254
Cross-site Scripting (DOM-based XSS) (CWE-79) Arbitrary code execution Important 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVE-2026-48255
Cross-site Scripting (DOM-based XSS) (CWE-79) Arbitrary code execution Important 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVE-2026-48257
Cross-site Scripting (DOM-based XSS) (CWE-79) Arbitrary code execution Important 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVE-2026-48260
Cross-site Scripting (DOM-based XSS) (CWE-79) Arbitrary code execution Important 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVE-2026-48261
Cross-site Scripting (DOM-based XSS) (CWE-79) Privilege escalation Important 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVE-2026-48262

 

메모

If a customer is using Apache httpd in a proxy with a non-default configuration, they may be impacted by CVE-2023-25690 - please read more here: https://httpd.apache.org/security/vulnerabilities_24.html

Acknowledgments

Adobe would like to thank the following for reporting these issues and for working with Adobe to help protect our customers: 

  • green-jam - CVE-2026-48253, CVE-2026-48254, CVE-2026-48255, CVE-2026-48257, CVE-2026-48260, CVE-2026-48261, CVE-2026-48262
  • Dylan Pindur, Adam Kues, and Patrik Grobshäuser of Assetnote - CVE-2026-48252, CVE-2026-48259, CVE-2026-48263, CVE-2026-48310, CVE-2026-48355, CVE-2026-48359

NOTE: Adobe has a public bug bounty program with HackerOne. If you are interested in working with Adobe as an external security researcher, please check out https://hackerone.com/adobe

 

 

Revisions

December 18, 2025: Added CVE-2025-64538 

December 10, 2025: Removed CVE-2025-64540

December 24, 2025: Added note - "AEM 6.5 and LTS versions are not impacted by the following CVEs: CVE-2025-64537, CVE-2025-64538, CVE-2025-64539."


자세한 내용은 https://helpx.adobe.com/kr/security.html을 방문하거나 PSIRT@adobe.com으로 이메일을 보내십시오.

Adobe, Inc.

쉽고 빠르게 지원 받기

신규 사용자이신가요?