Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.6
CVE-2026-82000: Adobe Experience Manager Forms JEE lets attackers reach internal systems
CVE-2026-82000 · published 1 day ago
Summary
The Forms JEE component of Adobe Experience Manager 6.5 can be tricked into making its own requests to other servers inside your network. An attacker with limited access could use this to view or interact with internal resources they should not see, potentially gaining higher privileges. Apply the latest Adobe patches and restrict the server's outbound connections to only trusted destinations.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| adobe | aem 6.5 forms jee | <= 6.5.25 |
| adobe | aem 6.5 lts forms jee | <= 6.5 LTS SP2 |
Original advisory text
Adobe Experience Manager Forms JEE | Server-Side Request Forgery (SSRF) (CWE-918)
Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope is changed.
Severity
9.6
Critical
CVSS 3.1: 9.6 (MITRE)
Type
CWE-918Server-Side Request Forgery (SSRF)
Timeline
Published22 Sep 2026
Updated23 Sep 2026
First seen22 Sep 2026
Track software like this
Free during beta