"Perfect" Adobe Experience Manager vulnerability is being exploited (CVE-2025-54253)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-54253 | Pre-Auth RCE in Adobe Experience Manager Forms via Struts DevMode Misconfiguration CVE-2025-54253 is a critical (CVSS 3.1: 10.0) misconfiguration vulnerability — classified as incorrect authorization (CWE-863) — in Adobe Experience Manager (AEM) Forms versions 6.5.23 and earlier, which the referenced public research ties to Apache Struts DevMode being exposed on AEM Forms deployments. It is triggerable over the network without authentication or user interaction by sending crafted requests to the exposed dev-mode functionality, allowing an attacker to bypass security mechanisms and execute arbitrary code. Because the exploitation scope is changed, a successful compromise can impact components beyond the vulnerable service, with high impact to confidentiality, integrity, and availability. Any organization running AEM Forms 6.5.23 or earlier — particularly internet-facing Forms servers at enterprises and government agencies — is affected. The flaw is being actively exploited in the wild: CISA added it to the KEV catalog on 2025-10-15, a public proof-of-concept is available, and EPSS assigns an 87.5% probability of exploitation within 30 days (100th percentile). Do: Upgrade AEM Forms to a release newer than 6.5.23 using the patched service pack/security update in Adobe's security bulletin, and apply vendor-recommended mitigations (e.g., disabling or restricting access to the exposed Struts DevMode endpoints) where patching is delayed. Audit internet-facing AEM Forms instances for exposed dev-mode endpoints and review logs for signs of exploitation. Federal agencies under BOD 22-01 must apply the required mitigations per vendor instructions or discontinue use of the product by the KEV due date. | 10.0 | 88% | KEV PoC |
| largelikely tens of thousands of AEM Forms servers/deployments (thousands of them internet-exposed); order-of-magnitude estimate, no official install counts | |
| CVE-2025-54254 | XXE Arbitrary File-Read in Adobe Experience Manager Forms 6.5 CVE-2025-54254 is an XML External Entity (XXE) injection flaw (CWE-611) in Adobe Experience Manager (AEM) Forms version 6.5.23 and earlier, caused by improper restriction of external entity references when the application processes XML input. It is exploitable over the network by an unauthenticated attacker and requires no user interaction. Successful exploitation allows arbitrary file reads from the server's local file system, and the 'scope changed' element of the CVSS score indicates impact can extend beyond the vulnerable component's security scope, potentially exposing sensitive files such as configuration data and credentials; integrity and availability are unaffected. Any organization running AEM Forms 6.5.23 or earlier is in scope, especially where Forms endpoints are reachable from the internet. This specific CVE is not in CISA KEV and has no catalogued PoC of its own, but headlines report a public PoC for the AEM Forms flaws fixed in the same Adobe advisory, the sibling AEM Forms flaw CVE-2025-54253 (CVSS 10.0) is already under active attack, and the 77.1% EPSS score (100th percentile) signals a high probability of exploitation within 30 days. Do: Upgrade AEM Forms to a release newer than 6.5.23 by applying Adobe's current AEM/AEM Forms security update, which also addresses the actively exploited sibling flaw CVE-2025-54253. Until patched, restrict internet exposure of AEM Forms endpoints and harden XML parsing (disable external entity resolution where configurable). Review server and access logs for suspicious XML requests containing external entity or file:// references and for unexpected file reads, and prioritize patching since exploitation of the related flaw is already confirmed in the wild. | 8.6 | 77% |
| largelikely tens of thousands of deployments (~10,000+ internet-facing AEM instances in public scans; AEM Forms widely embedded in enterprise stacks) |
Full article369 words · extracted from helpnetsecurity.com · click to collapse
CISA has added CVE-2025-54253, a misconfiguration vulnerability in Adobe Experience Manager (AEM) Forms on Java Enterprise Edition (JEE), to its Known Exploited Vulnerabilities catalog, thus warning of detected in-the-wild exploitation.

Adobe fixed the vulnerability in August 2025, along with CVE-2025-54254, an Improper Restriction of XML External Entity Reference vulnerability in the same solution.
But with a proof-of-concept (PoC) exploit for the two flaws having been made public before that, it was only a matter of time until attackers would try to leverage them.
That said, it’s currently unkown why only CVE-2025-54253 has been added to the KEV catalog and whether the attackers have used the public PoC exploit as a starting point for their own. CISA, unfortunately, does not include any information about the attack(s) into the KEV catalog.
CVE-2025-54253 allows remote code execution
CVE-2025-54253 is a misconfiguration in AEM Forms that leaves Apache Struts “devMode” enabled in the admin UI, and an authentication bypass. It lets unauthenticated attackers run expressions that the Struts framework will evaluate, and can lead to remote code execution. 
It can be exploited in low-complexity attacks that require no user interaction.
The vulnerability affects Adobe Experience Manager (AEM) Forms on JEE versions 6.5.23.0 and earlier.
Shubham Shah and Adam Kues, the researchers who reported the two flaws and published the PoC exploit when Adobe failed to address them within 90 days, previously explained that Adobe Experience Manager Forms can be either co-deployed with the standard AEM installation or deployed standalone on a J2EE-compatible server.
“The vulnerabilities [we found] are primarily applicable to standalone deployments of AEM Forms via a J2EE-compatible server such as JBoss,” they said.
Since a patch wasn’t available at the time, they advised users to restrict access to Adobe Experience Manager Forms from the internet when deployed as a standalone application.
But with fixes available for a couple of months now and in light of the confirmation of in-the-wild exploitation, users should upgrade to version 6.5.0-0108 or later as soon as possible.
CISA has ordered Federal Civilian Executive Branch (FCEB) agencies to patch their systems by November 5, 2025.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/10/16/adobe-experience-manager-vulnerability-exploited-cve-2025-54253/