CVE-2025-49533: Adobe Experience Manager (MS) | Deserialization of Untrusted Data (CWE-502)
Published Jul 8, 2025
·Updated
Adobe Experience Manager (MS) versions 6.5.23.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction. Scope is unchanged.
Affected Software
2 affected components
Adobe Experience Manager (MS)<6.5.23.0
Adobe Experience Manager<=6.5.23.0
Event History
Jul 8, 2025
CVE Published
via MITRE·09:32 PM
Data Sourced
via MITRE·09:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Aug 5, 2025
News Published
via BleepingComputer·07:02 PM
News Published
via BleepingComputer·07:03 PM
Oct 16, 2025
News Published
via BleepingComputer·02:28 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-49533?
CVE-2025-49533 has a high severity rating due to its potential for arbitrary code execution.
2
How do I fix CVE-2025-49533?
To fix CVE-2025-49533, upgrade to Adobe Experience Manager (MS) version 6.5.23.1 or later.
3
What versions of Adobe Experience Manager (MS) are affected by CVE-2025-49533?
Versions 6.5.23.0 and earlier of Adobe Experience Manager (MS) are affected by CVE-2025-49533.
4
Does exploitation of CVE-2025-49533 require user interaction?
No, exploitation of CVE-2025-49533 does not require user interaction.
5
What are the consequences of a successful exploit of CVE-2025-49533?
Successful exploitation of CVE-2025-49533 could allow an attacker to execute arbitrary code on the affected system.