PT-2025-31949 · Adobe · Experience Manager

Adam Kues

+1

·

Published

2025-08-05

·

Updated

2025-09-26

·

CVE-2025-54253

CVSS v3.1
10
VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

**Name of the Vulnerable Software and Affected Versions**

Adobe Experience Manager versions 6.5.23 and earlier

**Description**

Adobe Experience Manager is affected by a misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this vulnerability to bypass security mechanisms and execute code without user interaction, and the scope of the vulnerability has been changed. Public Proof-of-Concept (PoC) exploits are available. Approximately 5,200 instances of Adobe Experience Manager are discoverable online.

**Recommendations**

Adobe Experience Manager versions prior to 6.5.24 are affected.

Update to a newer version to address this vulnerability.

As a temporary workaround, restrict internet access to vulnerable systems.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2025-09420
CVE-2025-54253

Affected Products

Experience Manager