Vulnerability record · CVE-2025-54253 · published 5 August 2025
CVE-2025-54253: Adobe Experience Manager Forms misconfiguration allows pre-auth code execution
Adobe · Experience Manager Forms
Adobe Experience Manager Forms 6.5.23 and earlier contain a misconfiguration (CWE-863, incorrect authorization) that lets an attacker bypass security mechanisms and execute arbitrary code. The flaw is network-reachable, needs no authentication or user interaction, and changes scope, making it a full-impact remote code execution issue in a widely deployed enterprise platform.
Description
Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable code execution with CVSS 10.0, KEV listing, and near-top EPSS percentile makes this an urgent patch-first issue.
What it is
Adobe Experience Manager Forms 6.5.23 and earlier contain a misconfiguration (CWE-863, incorrect authorization) that lets an attacker bypass security mechanisms and execute arbitrary code. The flaw is network-reachable, needs no authentication or user interaction, and changes scope, making it a full-impact remote code execution issue in a widely deployed enterprise platform.
Impact
An unauthenticated attacker can execute arbitrary code on the affected server, gaining control of the AEM Forms instance and potentially pivoting to connected systems given the changed scope.
Attack surface
Reachable over the network via the affected AEM Forms service with no authentication and no user interaction required, per the CVSS vector (AV:N/AC:L/PR:N/UI:N). The description does not name the specific endpoint or component.
Exploitation
CISA added this to KEV on 2025-10-15 with a remediation due date of 2025-11-05, and a third-party advisory is tagged as an exploit reference, indicating active exploitation. EPSS is 0.87989 (99.756th percentile), consistent with high likelihood of exploitation.
What to do
- Apply the vendor fix from Adobe security bulletin APSB25-82 for AEM Forms 6.5.23 and earlier, or upgrade to a patched release.
- If patching cannot be completed by the CISA due date, follow BOD 22-01 guidance for cloud services or discontinue use of the product.
- Restrict network access to AEM Forms endpoints to trusted sources and place them behind authentication-aware controls where feasible.
- Review AEM Forms configuration against vendor hardening guidance to close the authorization misconfiguration.
- Monitor Adobe and CISA advisories for updated mitigation instructions.
Detection
- Hunt for unexpected child processes or command execution spawned by the AEM Forms/Java service account.
- Review web and application logs for anomalous requests to AEM Forms endpoints, especially unauthenticated access patterns.
- Alert on outbound network connections from AEM Forms hosts to unfamiliar destinations.
- Monitor for file writes or new artifacts in AEM installation and web directories outside normal deployment windows.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-54253 to the Known Exploited Vulnerabilities catalog on 15 October 2025 as "Adobe Experience Manager Forms Code Execution Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 5 November 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://helpx.adobe.com/security/products/aem-forms/apsb25-82.html | Vendor Advisory |
| https://slcyber.io/assetnote-security-research-center/struts-devmode-in-2025-critical-pre-auth-vulnerabilities-in-adobe- | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-54253 | Third Party AdvisoryUS Government Resource |
Track CVE-2025-54253 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-54253), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.