CVE-2016-0957: Adobe Dispatcher

High severity, CVSS 7.5. EPSS: 52% chance of exploitation in the next 30 days.

Dispatcher before 4.1.5 in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0 does not properly implement a URL filter, which allows remote attackers to bypass dispatcher rules via unspecified vectors.

Affected products

  • Adobe Dispatcher: up to and including 4.1.4
  • Adobe Experience Manager: version 5.6.1 only; version 6.0.0 only; version 6.1.0 only

Published 2016-02-10. Last modified 2026-06-17.