ZeroHour

CVE-2025-49533

large

Unauthenticated Deserialization RCE in Adobe Experience Manager 6.5

CVSS 3.1
9.8 critical
EPSS
53%p99
Published
()
Modified
AI analysis

Adobe Experience Manager (MS) versions 6.5.23.0 and earlier contain a critical deserialization of untrusted data flaw (CWE-502) that an attacker can trigger remotely over the network without authentication and without any user interaction. By supplying maliciously crafted serialized data to a vulnerable AEM instance, the attacker achieves arbitrary code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1: 9.8). Affected organizations are those running on-prem AEM on the 6.5 release line at 6.5.23.0 or earlier, including AEM Forms deployments referenced in related coverage of Adobe's patch release. As of the available data the flaw is not yet in CISA's KEV and there is no confirmed in-the-wild exploitation, but related news reports a public proof of concept for the AEM Forms vulnerabilities fixed in the same advisory, and a 52.9% EPSS (99th percentile) indicates a high likelihood of exploitation within 30 days.

What to do: Upgrade all AEM 6.5 deployments to a service pack newer than 6.5.23.0 per Adobe's security advisory, prioritizing internet-facing author/publish instances and AEM Forms (JEE) servers given the high EPSS. Until patched, restrict network access to AEM application endpoints and review edge/WAF rules for Java deserialization attack patterns. Hunt logs for signs of exploitation, monitor for KEV addition and new PoC releases, and treat patching this 9.8-CVSS, no-authentication RCE as an urgent priority.

Affected
Adobe Experience Manager (MS)6.5.23.0 and earlier
Estimated exposure
large≈10,000–100,000 on-prem AEM 6.5 instances worldwide — AEM 6.5 is Adobe's current on-prem enterprise CMS/Forms release line used by thousands of enterprise customers who typically run multiple author and publish servers, so aggregate unpatched instances plausibly fall in the tens of thousands,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe Experience Manager (MS) versions 6.5.23.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction. Scope is unchanged.

Vendors
adobe
Products
experience manager
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news