PT-2025-31949 · Adobe · Experience Manager
Adam Kues
+1
·
Published
2025-08-05
·
Updated
2025-08-07
·
CVE-2025-54253
CVSS v3.1
10
10
Critical
Base vector | Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
**Name of the Vulnerable Software and Affected Versions:**
Adobe Experience Manager versions 6.5.23 and earlier
**Description:**
Adobe Experience Manager versions 6.5.23 and earlier are affected by a misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require user interaction, and the scope is changed. Approximately 5,200 instances have been found online. Public proof-of-concept exploits are available.
**Recommendations:**
Update Adobe Experience Manager to a version later than 6.5.23.
Fix
RCE
Weakness Enumeration
Related Identifiers
CVE-2025-54253
Affected Products
Experience Manager
References · 20
- https://nvd.nist.gov/vuln/detail/CVE-2025-54253 · Security Note
- https://helpx.adobe.com/security/products/aem-forms/apsb25-82.html · Reddit Post, Vendor Advisory
- https://twitter.com/rapidriskradar/status/1953202148423938266 · Twitter Post
- https://twitter.com/RedLegg/status/1953116374974218397 · Twitter Post
- https://twitter.com/BaseFortify/status/1953019091058393312 · Twitter Post
- https://twitter.com/fridaysecurity/status/1952887858697572400 · Twitter Post
- https://twitter.com/dCypherIO/status/1953116358956241014 · Twitter Post
- https://slcyber.io/assetnote-security-research-center/struts-devmode-in-2025-critical-pre-auth-vulnerabilities-in-adobe-experience-manager-forms · Note
- https://twitter.com/CCBalert/status/1953102591694356915 · Twitter Post
- https://twitter.com/TweetThreatNews/status/1952838255524622390 · Twitter Post
- https://twitter.com/fofabot/status/1952984906914775140 · Twitter Post
- https://twitter.com/CveFindCom/status/1952786942141030543 · Twitter Post
- https://twitter.com/Strivehawk/status/1952866296481141038 · Twitter Post
- https://twitter.com/zoomeye_team/status/1953041189550358723 · Twitter Post
- https://twitter.com/RedSiege/status/1952832356793925933 · Twitter Post