CVE-2025-49533
largeUnauthenticated Deserialization RCE in Adobe Experience Manager 6.5
Adobe Experience Manager (MS) versions 6.5.23.0 and earlier contain a critical deserialization of untrusted data flaw (CWE-502) that an attacker can trigger remotely over the network without authentication and without any user interaction. By supplying maliciously crafted serialized data to a vulnerable AEM instance, the attacker achieves arbitrary code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1: 9.8). Affected organizations are those running on-prem AEM on the 6.5 release line at 6.5.23.0 or earlier, including AEM Forms deployments referenced in related coverage of Adobe's patch release. As of the available data the flaw is not yet in CISA's KEV and there is no confirmed in-the-wild exploitation, but related news reports a public proof of concept for the AEM Forms vulnerabilities fixed in the same advisory, and a 52.9% EPSS (99th percentile) indicates a high likelihood of exploitation within 30 days.
What to do: Upgrade all AEM 6.5 deployments to a service pack newer than 6.5.23.0 per Adobe's security advisory, prioritizing internet-facing author/publish instances and AEM Forms (JEE) servers given the high EPSS. Until patched, restrict network access to AEM application endpoints and review edge/WAF rules for Java deserialization attack patterns. Hunt logs for signs of exploitation, monitor for KEV addition and new PoC releases, and treat patching this 9.8-CVSS, no-authentication RCE as an urgent priority.
| Adobe Experience Manager (MS) | 6.5.23.0 and earlier |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Adobe Experience Manager (MS) versions 6.5.23.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction. Scope is unchanged.
- Vendors
- adobe
- Products
- experience manager
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H