CVE-2025-54253
KEV PoC largePre-Auth RCE in Adobe Experience Manager Forms via Struts DevMode Misconfiguration
CISA: Adobe Experience Manager Forms Code Execution Vulnerability
CVE-2025-54253 is a critical (CVSS 3.1: 10.0) misconfiguration vulnerability — classified as incorrect authorization (CWE-863) — in Adobe Experience Manager (AEM) Forms versions 6.5.23 and earlier, which the referenced public research ties to Apache Struts DevMode being exposed on AEM Forms deployments. It is triggerable over the network without authentication or user interaction by sending crafted requests to the exposed dev-mode functionality, allowing an attacker to bypass security mechanisms and execute arbitrary code. Because the exploitation scope is changed, a successful compromise can impact components beyond the vulnerable service, with high impact to confidentiality, integrity, and availability. Any organization running AEM Forms 6.5.23 or earlier — particularly internet-facing Forms servers at enterprises and government agencies — is affected. The flaw is being actively exploited in the wild: CISA added it to the KEV catalog on 2025-10-15, a public proof-of-concept is available, and EPSS assigns an 87.5% probability of exploitation within 30 days (100th percentile).
What to do: Upgrade AEM Forms to a release newer than 6.5.23 using the patched service pack/security update in Adobe's security bulletin, and apply vendor-recommended mitigations (e.g., disabling or restricting access to the exposed Struts DevMode endpoints) where patching is delayed. Audit internet-facing AEM Forms instances for exposed dev-mode endpoints and review logs for signs of exploitation. Federal agencies under BOD 22-01 must apply the required mitigations per vendor instructions or discontinue use of the product by the KEV due date.
| Adobe Experience Manager (AEM) Forms | 6.5.23 and earlier |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.
- Affected
- Adobe Experience Manager (AEM) Forms
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- adobe
- Products
- experience manager forms
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H