PT-2025-31949 · Adobe · Experience Manager

Adam Kues

+1

·

Published

2025-08-05

·

Updated

2025-08-07

·

CVE-2025-54253

CVSS v3.1
10
VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

**Name of the Vulnerable Software and Affected Versions:**

Adobe Experience Manager versions 6.5.23 and earlier

**Description:**

Adobe Experience Manager versions 6.5.23 and earlier are affected by a misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require user interaction, and the scope is changed. Approximately 5,200 instances have been found online. Public proof-of-concept exploits are available.

**Recommendations:**

Update Adobe Experience Manager to a version later than 6.5.23.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-54253

Affected Products

Experience Manager