← Vulnerability feed

Vulnerability record · CVE-2025-49533 · published 8 July 2025

CVE-2025-49533: Adobe Experience Manager untrusted deserialization enables remote code execution

Adobe · Experience Manager

Adobe Experience Manager (MS) versions 6.5.23.0 and earlier contain a deserialization of untrusted data flaw (CWE-502) that can lead to arbitrary code execution. The vulnerability is network reachable with no authentication or user interaction required, making it a severe risk for exposed AEM instances.

9.8 CVSS 3.1 Critical EPSS 53% · top 1.1% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score
53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Adobe Experience Manager (MS) versions 6.5.23.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction. Scope is unchanged.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction required, and high EPSS probability indicate an urgent patching need.

What it is

Adobe Experience Manager (MS) versions 6.5.23.0 and earlier contain a deserialization of untrusted data flaw (CWE-502) that can lead to arbitrary code execution. The vulnerability is network reachable with no authentication or user interaction required, making it a severe risk for exposed AEM instances.

Impact

An unauthenticated attacker can execute arbitrary code on the affected server, potentially leading to full system compromise. The CVSS vector indicates high confidentiality, integrity, and availability impact.

Attack surface

The flaw is reachable over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N). Any exposed AEM endpoint that processes untrusted serialized data could be a vector.

Exploitation

The CVE is not listed in CISA KEV, but EPSS indicates a 52.9% probability of exploitation in the next 30 days (98.9th percentile). No public exploit references are provided beyond the vendor advisory.

What to do

  • Apply the vendor patch referenced in Adobe security advisory APSB25-67 immediately.
  • If patching is not possible, restrict network access to AEM instances to trusted sources only.
  • Monitor for and block deserialization of untrusted data at the application or network layer if feasible.
  • Review and harden any custom code that performs deserialization of user-supplied data.
  • Enable logging and alerting for suspicious serialized payloads or unexpected process execution.

Detection

  • Monitor for unusual outbound network connections or process creation on AEM servers.
  • Inspect application logs for deserialization errors or unexpected class loading.
  • Use endpoint detection to flag suspicious child processes spawned by the AEM Java process.
  • Review web server logs for requests containing serialized Java objects (e.g., base64-encoded 'rO0' headers).

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-49533 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2026-19232Adobe experience manager incorrect authorization vulnerabilityAdobe Experience Manager is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the …EPSS 0.59%9.8CVE-2024-26029Adobe experience manager improper access control vulnerabilityAdobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature…EPSS 0.89%9.8CVE-2021-40722Adobe experience manager xml external entity (xxe) vulnerabilityAEM Forms Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by an XML External Entity (XXE) injection vulnerability that c…EPSS 3.3%9.8CVE-2019-8088Adobe experience manager command injection vulnerabilityAdobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a command injection vulnerability. Successful exploitation could lead to arbitrary code …EPSS 5.8%9.8CVE-2019-7964Adobe experience manager vulnerabilityAdobe Experience Manager versions 6.5, and 6.4 have an authentication bypass vulnerability. Successful exploitation could lead to remote code executi…EPSS 10%9.8CVE-2017-3108Adobe experience manager unrestricted file upload vulnerabilityAdobe Experience Manager 6.2 and earlier has a malicious file execution vulnerability.EPSS 8.6%9.6CVE-2026-48359Adobe experience manager xml external entity (xxe) vulnerabilityAdobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary…EPSS 1.0%9.6CVE-2026-48259Adobe experience manager server-side request forgery (ssrf) vulnerabilityAdobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the conte…EPSS 0.90%

Source: NIST National Vulnerability Database (record CVE-2025-49533), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.