Cyber & AI intelligence
Wasteland.
Briefs indexed2597
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-19232 2026-09-08

CVE-2026-19232: Critical Adobe Experience Manager Authorization Flaw Scores 9.9

"Adobe disclosed an Incorrect Authorization vulnerability in Adobe Experience Manager that, per the vendor advisory, could result in arbitrary code execution and carries a CVSS 3.1 base score of 9.9."

Adobe disclosed an Incorrect Authorization vulnerability in Adobe Experience Manager that, per the vendor advisory, could result in arbitrary code execution and carries a CVSS 3.1 base score of 9.9.

What Is It

CVE-2026-19232 is an Incorrect Authorization flaw (CWE-863) in Adobe Experience Manager. According to Adobe's advisory (APSB26-98), the vulnerability "could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session." The CVSS metrics indicate that an attacker holding only low privileges could reach this outcome, and that exploitation does not require user interaction.

The CVSS 3.1 vector is AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, network-reachable, low attack complexity, only low privileges needed, no user interaction, and a changed scope, with high impact to confidentiality, integrity, and availability. The record was published 2026-09-08 and currently sits in "Awaiting Analysis" status at NVD.

Why It Matters

The 9.9 score is driven by the combination of low privilege requirement and changed scope: an attacker who already holds a minimal AEM account could break out of that authorization boundary and affect resources beyond the vulnerable component. AEM is a content management platform typically deployed as internet-facing infrastructure, which aligns with the NETWORK attack vector. No user interaction is required, removing the need for any social engineering step.

CVE-2026-19232 does not appear in the CISA Known Exploited Vulnerabilities catalog as of this writing, so active exploitation is not confirmed at this time.

What's Vulnerable

Per Adobe's affected-product table in APSB26-98:

Patch Status

Fixed releases are available. Cloud Service users should be on 2026.8.0 or later. On-premises 6.5 LTS deployments should move to SP3, and AEM 6.5 deployments to 6.5.25. Adobe's security bulletin APSB26-98 is the authoritative reference for the fix. Because the CVE is not listed in the CISA KEV catalog, no BOD 22-01 remediation deadline applies to federal civilian agencies; organizations should patch on their normal critical-severity timeline.

Sources