← Vulnerability feed

Vulnerability record · CVE-2025-54253 · published 5 August 2025

CVE-2025-54253: Adobe Experience Manager Forms misconfiguration allows pre-auth code execution

Adobe · Experience Manager Forms

Adobe Experience Manager Forms 6.5.23 and earlier contain a misconfiguration (CWE-863, incorrect authorization) that lets an attacker bypass security mechanisms and execute arbitrary code. The flaw is network-reachable, needs no authentication or user interaction, and changes scope, making it a full-impact remote code execution issue in a widely deployed enterprise platform.

10.0 CVSS 3.1 Critical CISA KEV since 15 Oct 2025 EPSS 88% · top 0.2% CWE-863 · Incorrect authorization
10.0CVSS 3.1 base score
88%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable code execution with CVSS 10.0, KEV listing, and near-top EPSS percentile makes this an urgent patch-first issue.

What it is

Adobe Experience Manager Forms 6.5.23 and earlier contain a misconfiguration (CWE-863, incorrect authorization) that lets an attacker bypass security mechanisms and execute arbitrary code. The flaw is network-reachable, needs no authentication or user interaction, and changes scope, making it a full-impact remote code execution issue in a widely deployed enterprise platform.

Impact

An unauthenticated attacker can execute arbitrary code on the affected server, gaining control of the AEM Forms instance and potentially pivoting to connected systems given the changed scope.

Attack surface

Reachable over the network via the affected AEM Forms service with no authentication and no user interaction required, per the CVSS vector (AV:N/AC:L/PR:N/UI:N). The description does not name the specific endpoint or component.

Exploitation

CISA added this to KEV on 2025-10-15 with a remediation due date of 2025-11-05, and a third-party advisory is tagged as an exploit reference, indicating active exploitation. EPSS is 0.87989 (99.756th percentile), consistent with high likelihood of exploitation.

What to do

  • Apply the vendor fix from Adobe security bulletin APSB25-82 for AEM Forms 6.5.23 and earlier, or upgrade to a patched release.
  • If patching cannot be completed by the CISA due date, follow BOD 22-01 guidance for cloud services or discontinue use of the product.
  • Restrict network access to AEM Forms endpoints to trusted sources and place them behind authentication-aware controls where feasible.
  • Review AEM Forms configuration against vendor hardening guidance to close the authorization misconfiguration.
  • Monitor Adobe and CISA advisories for updated mitigation instructions.

Detection

  • Hunt for unexpected child processes or command execution spawned by the AEM Forms/Java service account.
  • Review web and application logs for anomalous requests to AEM Forms endpoints, especially unauthenticated access patterns.
  • Alert on outbound network connections from AEM Forms hosts to unfamiliar destinations.
  • Monitor for file writes or new artifacts in AEM installation and web directories outside normal deployment windows.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-54253 to the Known Exploited Vulnerabilities catalog on 15 October 2025 as "Adobe Experience Manager Forms Code Execution Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 5 November 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-54253 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.0CVE-2020-9732Adobe experience manager cross-site scripting vulnerabilityThe AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) are affected by a stored XSS vulnerability that allows users with 'Auth…EPSS 2.8%8.6CVE-2025-54254Adobe Experience Manager Forms XXE allows arbitrary file readAdobe Experience Manager Forms versions 6.5.23 and earlier are affected by an XML External Entity (XXE) vulnerability (CWE-611) that permits arbitrar…EPSS 77%analysed7.5CVE-2020-9733Adobe experience manager information exposure vulnerabilityAn AEM java servlet in AEM versions 6.5.5.0 (and below) and 6.4.8.1 (and below) executes with the permissions of a high privileged service user. If e…EPSS 3.8%7.5CVE-2017-3067Adobe experience manager forms information exposure vulnerabilityAdobe Experience Manager Forms versions 6.2, 6.1, 6.0 have an information disclosure vulnerability resulting from abuse of the pre-population service…EPSS 4.8%6.1CVE-2019-8089Adobe experience manager forms cross-site scripting vulnerabilityAdobe Experience Manager Forms versions 6.3-6.5 have a reflected cross-site scripting vulnerability. Successful exploitation could lead to sensitive …EPSS 1.5%6.1CVE-2019-7129Adobe experience manager forms cross-site scripting vulnerabilityAdobe Experience Manager Forms versions 6.2, 6.3 and 6.4 have a stored cross-site scripting vulnerability. Successful exploitation could lead to sens…EPSS 1.6%6.1CVE-2016-6934Adobe experience manager forms cross-site scripting vulnerabilityAdobe Experience Manager Forms versions 6.2 and earlier, LiveCycle 11.0.1, LiveCycle 10.0.4 have an input validation issue in the PMAdmin module that…EPSS 2.6%9.1CVE-2026-71362Adobe commerce incorrect authorization vulnerabilityAdobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vul…KEVEPSS 88%

Source: NIST National Vulnerability Database (record CVE-2025-54253), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.