• News/
  • https://www.bleepingcomputer.com/news/security/cisa-maximum-severity-adobe-flaw-now-exploited-in-attacks/

CISA: Maximum-severity Adobe flaw now exploited in attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Oct 16, 2025
·
Updated

CISA has warned that attackers are actively exploiting a maximum-severity vulnerability in Adobe Experience Manager to execute code on unpatched systems. Tracked as CVE-2025-54253, this critical security flaw stems from a misconfiguration weakness that affects Adobe Experience Manager (AEM) Forms on JEE versions 6.5.23 and earlier. Successful exploitation can allow unauthenticated threat actors to bypass security mechanisms and execute arbitrary code remotely in low-complexity attacks that don't require user interaction. The flaw was discovered by Adam Kues and Shubham Shah of Searchlight Cyber, who disclosed it to Adobe on April 28th, together with two other issues (CVE-2025-54254 and CVE-2025-49533). However, Adobe patched only the latter in April, leaving the other two unfixed for over 90 days, until after the two security researchers published a write-up on July 29th detailing how the vulnerabilities work and how they can be exploited. Adobe finally released security updates on August 9th to address the CVE-2025-54253 vulnerability, confirming that proof-of-concept exploit code was already publicly available. As Searchlight Cyber explained, CVE-2025-54253 is an authentication bypass that leads to remote code execution (RCE) via Struts DevMode. The researchers also advised admins to restrict Internet access to AEM Forms when deployed as a standalone application if they can't immediately patch the software. CISA has now added this vulnerability to its Known Exploited Vulne...

Read full article

Affected Software

1 affected component
Adobe Experience Manager=6.5.23
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a maximum-severity vulnerability in Adobe Experience Manager that is being actively exploited by attackers.

2

What is the severity level of the Adobe vulnerability mentioned?

The vulnerability is categorized as maximum-severity and is tracked as CVE-2025-54253.

3

What type of security issue does this vulnerability allow?

The vulnerability allows attackers to execute code on unpatched systems.

4

Which specific product version of Adobe is affected by this flaw?

The affected product is Adobe Experience Manager version 6.5.23.

5

What agency has issued a warning about this Adobe vulnerability?

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding this vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203