ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Adobe patches critical Adobe Experience Manager Forms vulnerabilities with public PoC

criticalExploit / PoC exploited in the wildimportance 60CVE-2025-54253CVE-2025-54254CVE-2025-49533

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-49533
Unauthenticated Deserialization RCE in Adobe Experience Manager 6.5

Adobe Experience Manager (MS) versions 6.5.23.0 and earlier contain a critical deserialization of untrusted data flaw (CWE-502) that an attacker can trigger remotely over the network without authentication and without any user interaction. By supplying maliciously crafted serialized data to a vulnerable AEM instance, the attacker achieves arbitrary code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1: 9.8). Affected organizations are those running on-prem AEM on the 6.5 release line at 6.5.23.0 or earlier, including AEM Forms deployments referenced in related coverage of Adobe's patch release. As of the available data the flaw is not yet in CISA's KEV and there is no confirmed in-the-wild exploitation, but related news reports a public proof of concept for the AEM Forms vulnerabilities fixed in the same advisory, and a 52.9% EPSS (99th percentile) indicates a high likelihood of exploitation within 30 days.

Do: Upgrade all AEM 6.5 deployments to a service pack newer than 6.5.23.0 per Adobe's security advisory, prioritizing internet-facing author/publish instances and AEM Forms (JEE) servers given the high EPSS. Until patched, restrict network access to AEM application endpoints and review edge/WAF rules for Java deserialization attack patterns. Hunt logs for signs of exploitation, monitor for KEV addition and new PoC releases, and treat patching this 9.8-CVSS, no-authentication RCE as an urgent priority.

9.853%
  • Adobe Experience Manager (MS) 6.5.23.0 and earlier
large≈10,000–100,000 on-prem AEM 6.5 instances worldwide
CVE-2025-54253
Pre-Auth RCE in Adobe Experience Manager Forms via Struts DevMode Misconfiguration

CVE-2025-54253 is a critical (CVSS 3.1: 10.0) misconfiguration vulnerability — classified as incorrect authorization (CWE-863) — in Adobe Experience Manager (AEM) Forms versions 6.5.23 and earlier, which the referenced public research ties to Apache Struts DevMode being exposed on AEM Forms deployments. It is triggerable over the network without authentication or user interaction by sending crafted requests to the exposed dev-mode functionality, allowing an attacker to bypass security mechanisms and execute arbitrary code. Because the exploitation scope is changed, a successful compromise can impact components beyond the vulnerable service, with high impact to confidentiality, integrity, and availability. Any organization running AEM Forms 6.5.23 or earlier — particularly internet-facing Forms servers at enterprises and government agencies — is affected. The flaw is being actively exploited in the wild: CISA added it to the KEV catalog on 2025-10-15, a public proof-of-concept is available, and EPSS assigns an 87.5% probability of exploitation within 30 days (100th percentile).

Do: Upgrade AEM Forms to a release newer than 6.5.23 using the patched service pack/security update in Adobe's security bulletin, and apply vendor-recommended mitigations (e.g., disabling or restricting access to the exposed Struts DevMode endpoints) where patching is delayed. Audit internet-facing AEM Forms instances for exposed dev-mode endpoints and review logs for signs of exploitation. Federal agencies under BOD 22-01 must apply the required mitigations per vendor instructions or discontinue use of the product by the KEV due date.

10.088% KEV PoC
  • Adobe Experience Manager (AEM) Forms 6.5.23 and earlier
largelikely tens of thousands of AEM Forms servers/deployments (thousands of them internet-exposed); order-of-magnitude estimate, no official install counts
CVE-2025-54254
XXE Arbitrary File-Read in Adobe Experience Manager Forms 6.5

CVE-2025-54254 is an XML External Entity (XXE) injection flaw (CWE-611) in Adobe Experience Manager (AEM) Forms version 6.5.23 and earlier, caused by improper restriction of external entity references when the application processes XML input. It is exploitable over the network by an unauthenticated attacker and requires no user interaction. Successful exploitation allows arbitrary file reads from the server's local file system, and the 'scope changed' element of the CVSS score indicates impact can extend beyond the vulnerable component's security scope, potentially exposing sensitive files such as configuration data and credentials; integrity and availability are unaffected. Any organization running AEM Forms 6.5.23 or earlier is in scope, especially where Forms endpoints are reachable from the internet. This specific CVE is not in CISA KEV and has no catalogued PoC of its own, but headlines report a public PoC for the AEM Forms flaws fixed in the same Adobe advisory, the sibling AEM Forms flaw CVE-2025-54253 (CVSS 10.0) is already under active attack, and the 77.1% EPSS score (100th percentile) signals a high probability of exploitation within 30 days.

Do: Upgrade AEM Forms to a release newer than 6.5.23 by applying Adobe's current AEM/AEM Forms security update, which also addresses the actively exploited sibling flaw CVE-2025-54253. Until patched, restrict internet exposure of AEM Forms endpoints and harden XML parsing (disable external entity resolution where configurable). Review server and access logs for suspicious XML requests containing external entity or file:// references and for unexpected file reads, and prioritize patching since exploitation of the related flaw is already confirmed in the wild.

8.677%
  • Adobe Experience Manager Forms (AEM Forms) 6.5.23 and earlier
largelikely tens of thousands of deployments (~10,000+ internet-facing AEM instances in public scans; AEM Forms widely embedded in enterprise stacks)
Full article329 words · extracted from helpnetsecurity.com · click to collapse

Adobe has released an emergency security update for Adobe Experience Manager Forms on Java Enterprise Edition (JEE), which fix two critical vulnerabilities (CVE-2025-54253, CVE-2025-54254) with a publicly available proof-of-concept (PoC) exploit.

Details about the flaws have been public for days, and attackers may soon try their hand at exploiting them.

Adobe Experience Manager Forms vulnerabilities PoC

About the vulnerabilities

Shubham Shah and Adam Kues, with Searchlight Cyber’s Research Team, found three critical vulnerabilities in Adobe Experience Manager Forms earlier this year and reported it to Adobe:

  • CVE-2025-49533, a untrusted data deserialization vulnerability affecting Adobe Experience Manager (AEM) Forms on JEE versions 6.5.23.0 and earlier that could lead to code execution without the need for any user interaction. A fix for it was released by Adobe a month ago
  • CVE-2025-54254 and CVE-2025-54253, an improper restriction of XML External Entity reference flaw and a misconfiguration issue, respectively, and they affect Adobe Experience Manager (AEM) Forms on JEE versions 6.5.23.0 and earlier.

    The former allows attackers to read arbitrary system files and the latter to bypass security mechanisms and execute code on the system. The fix for these has been released on Tuesday.

“Adobe Experience Manager Forms can be deployed in two different ways: either it is co-deployed with your standard AEM installation, or it is deployed standalone on a J2EE-compatible server. The vulnerabilities [we found] are primarily applicable to standalone deployments of AEM Forms via a J2EE-compatible server such as JBoss,” Shah and Kues explained.

While Adobe is not aware of these two vulnerabilities being exploited in the wild, it urges admins to install the update as soon as possible. (More details on how to do it are available here.)

If the security update can’t be implemented at this time, Searchlight Cyber researchers have advised organizations using AEM Forms in standalone mode to restrict access to the application to internal users/networks only.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/08/06/adobe-patches-critical-adobe-experience-manager-forms-vulnerabilities-with-public-poc/