Vulnerability record · CVE-2025-49533 · published 8 July 2025
CVE-2025-49533: Adobe Experience Manager untrusted deserialization enables remote code execution
Adobe · Experience Manager
Adobe Experience Manager (MS) versions 6.5.23.0 and earlier contain a deserialization of untrusted data flaw (CWE-502) that can lead to arbitrary code execution. The vulnerability is network reachable with no authentication or user interaction required, making it a severe risk for exposed AEM instances.
Description
Adobe Experience Manager (MS) versions 6.5.23.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction. Scope is unchanged.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, and high EPSS probability indicate an urgent patching need.
What it is
Adobe Experience Manager (MS) versions 6.5.23.0 and earlier contain a deserialization of untrusted data flaw (CWE-502) that can lead to arbitrary code execution. The vulnerability is network reachable with no authentication or user interaction required, making it a severe risk for exposed AEM instances.
Impact
An unauthenticated attacker can execute arbitrary code on the affected server, potentially leading to full system compromise. The CVSS vector indicates high confidentiality, integrity, and availability impact.
Attack surface
The flaw is reachable over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N). Any exposed AEM endpoint that processes untrusted serialized data could be a vector.
Exploitation
The CVE is not listed in CISA KEV, but EPSS indicates a 52.9% probability of exploitation in the next 30 days (98.9th percentile). No public exploit references are provided beyond the vendor advisory.
What to do
- Apply the vendor patch referenced in Adobe security advisory APSB25-67 immediately.
- If patching is not possible, restrict network access to AEM instances to trusted sources only.
- Monitor for and block deserialization of untrusted data at the application or network layer if feasible.
- Review and harden any custom code that performs deserialization of user-supplied data.
- Enable logging and alerting for suspicious serialized payloads or unexpected process execution.
Detection
- Monitor for unusual outbound network connections or process creation on AEM servers.
- Inspect application logs for deserialization errors or unexpected class loading.
- Use endpoint detection to flag suspicious child processes spawned by the AEM Java process.
- Review web server logs for requests containing serialized Java objects (e.g., base64-encoded 'rO0' headers).
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://helpx.adobe.com/security/products/aem-forms/apsb25-67.html | Vendor Advisory |
Track CVE-2025-49533 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-49533), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.