CISA Flags Adobe AEM Flaw with Perfect 10.0 Score — Already Under Active Attack
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2016-7836 | Unauthenticated RCE in SKYSEA Client View Management Console SKYSEA Client View Ver.11.221.03 and earlier contains an improper authentication flaw (CWE-287) in the processing of authentication on the TCP connection used with the management console program. An attacker with network reachability to that TCP service can send crafted authentication data that triggers remote code execution with no credentials, no user interaction, and no special conditions (CVSS 3.1: 9.8). Successful exploitation gives the attacker full code execution on the console side, with high impact to confidentiality, integrity, and availability, and potential access to the managed-client inventory the console controls. Organizations running SKYSEA Client View Ver.11.221.03 or earlier are affected; the product is a client/IT-asset management suite deployed largely by Japanese organizations. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on October 14, 2025, indicating confirmed in-the-wild exploitation, and EPSS currently estimates a 19.4% probability of exploitation within 30 days. Do: Upgrade SKYSEA Client View to a fixed release later than Ver.11.221.03 as directed in Sky Group's security advisory (https://www.skygroup.jp/security-info/170308.html), and inventory any console running Ver.11.221.03 or older. Until patched, restrict access to the management console TCP port from untrusted network segments and review console servers for signs of compromise. CISA KEV requires applying vendor mitigations or discontinuing use within the BOD 22-01 timeline. | 9.8 | 19% | KEV PoC |
| largeon the order of tens of thousands of management console deployments (product has a cumulative licensed base of millions of endpoints, concentrated in Japan) | |
| CVE-2025-54253 | Pre-Auth RCE in Adobe Experience Manager Forms via Struts DevMode Misconfiguration CVE-2025-54253 is a critical (CVSS 3.1: 10.0) misconfiguration vulnerability — classified as incorrect authorization (CWE-863) — in Adobe Experience Manager (AEM) Forms versions 6.5.23 and earlier, which the referenced public research ties to Apache Struts DevMode being exposed on AEM Forms deployments. It is triggerable over the network without authentication or user interaction by sending crafted requests to the exposed dev-mode functionality, allowing an attacker to bypass security mechanisms and execute arbitrary code. Because the exploitation scope is changed, a successful compromise can impact components beyond the vulnerable service, with high impact to confidentiality, integrity, and availability. Any organization running AEM Forms 6.5.23 or earlier — particularly internet-facing Forms servers at enterprises and government agencies — is affected. The flaw is being actively exploited in the wild: CISA added it to the KEV catalog on 2025-10-15, a public proof-of-concept is available, and EPSS assigns an 87.5% probability of exploitation within 30 days (100th percentile). Do: Upgrade AEM Forms to a release newer than 6.5.23 using the patched service pack/security update in Adobe's security bulletin, and apply vendor-recommended mitigations (e.g., disabling or restricting access to the exposed Struts DevMode endpoints) where patching is delayed. Audit internet-facing AEM Forms instances for exposed dev-mode endpoints and review logs for signs of exploitation. Federal agencies under BOD 22-01 must apply the required mitigations per vendor instructions or discontinue use of the product by the KEV due date. | 10.0 | 88% | KEV PoC |
| largelikely tens of thousands of AEM Forms servers/deployments (thousands of them internet-exposed); order-of-magnitude estimate, no official install counts | |
| CVE-2025-54254 | XXE Arbitrary File-Read in Adobe Experience Manager Forms 6.5 CVE-2025-54254 is an XML External Entity (XXE) injection flaw (CWE-611) in Adobe Experience Manager (AEM) Forms version 6.5.23 and earlier, caused by improper restriction of external entity references when the application processes XML input. It is exploitable over the network by an unauthenticated attacker and requires no user interaction. Successful exploitation allows arbitrary file reads from the server's local file system, and the 'scope changed' element of the CVSS score indicates impact can extend beyond the vulnerable component's security scope, potentially exposing sensitive files such as configuration data and credentials; integrity and availability are unaffected. Any organization running AEM Forms 6.5.23 or earlier is in scope, especially where Forms endpoints are reachable from the internet. This specific CVE is not in CISA KEV and has no catalogued PoC of its own, but headlines report a public PoC for the AEM Forms flaws fixed in the same Adobe advisory, the sibling AEM Forms flaw CVE-2025-54253 (CVSS 10.0) is already under active attack, and the 77.1% EPSS score (100th percentile) signals a high probability of exploitation within 30 days. Do: Upgrade AEM Forms to a release newer than 6.5.23 by applying Adobe's current AEM/AEM Forms security update, which also addresses the actively exploited sibling flaw CVE-2025-54253. Until patched, restrict internet exposure of AEM Forms endpoints and harden XML parsing (disable external entity resolution where configurable). Review server and access logs for suspicious XML requests containing external entity or file:// references and for unexpected file reads, and prioritize patching since exploitation of the related flaw is already confirmed in the wild. | 8.6 | 77% |
| largelikely tens of thousands of deployments (~10,000+ internet-facing AEM instances in public scans; AEM Forms widely embedded in enterprise stacks) |
Full article342 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananOct 16, 2025Vulnerability / Data Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical security flaw impacting Adobe Experience Manager to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.
The vulnerability in question is CVE-2025-54253 (CVSS score: 10.0), a maximum-severity misconfiguration bug that could result in arbitrary code execution.
According to Adobe, the shortcoming impacts Adobe Experience Manager (AEM) Forms on JEE versions 6.5.23.0 and earlier. It was addressed in version 6.5.0-0108 released early August 2025, alongside CVE-2025-54254 (CVSS score: 8.6).
Details of the two vulnerabilities were disclosed by Searchlight Cyber researchers Adam Kues and Shubham Shah in July 2025, describing CVE-2025-54253 as an "authentication bypass to [remote code execution] chain via Struts2 devmode" and CVE-2025-54254 as an XML external entity (XXE) injection within AEM Forms web services.
The flaw results from the dangerously exposed /adminui/debug servlet, which evaluates user-supplied OGNL expressions as Java code without requiring authentication or input validation," security company FireCompass noted. "The endpoint’s misuse enables attackers to execute arbitrary system commands with a single crafted HTTP request."
There is currently no information publicly available on how the security flaw is being exploited in real-world attacks, although Adobe acknowledged in its advisory that "CVE-2025-54253 and CVE-2025-54254 have a publicly available proof-of-concept."
In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are advised to apply the necessary fixes by November 5, 2025.
The development comes a day after CISA also added a critical improper authentication vulnerability in SKYSEA Client View (CVE-2016-7836, CVSS score: 9.8) to the KEV catalog. Japan Vulnerability Notes (JVN), in an advisory released in late 2016, said "attacks exploiting this vulnerability have been observed in the wild."
"SKYSEA Client View contains an improper authentication vulnerability that allows remote code execution via a flaw in processing authentication on the TCP connection with the management console program," the agency said.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/10/cisa-flags-adobe-aem-flaw-with-perfect.html