CISA has warned that attackers are actively exploiting a maximum-severity vulnerability in Adobe Experience Manager to execute code on unpatched systems. Tracked as CVE-2025-54253, this critical security flaw stems from a misconfiguration weakness that affects Adobe Experience Manager (AEM) Forms on JEE versions 6.5.23 and earlier. Successful exploitation can allow unauthenticated threat actors to bypass security mechanisms and execute arbitrary code remotely in low-complexity attacks that don't require user interaction. The flaw was discovered by Adam Kues and Shubham Shah of Searchlight Cyber, who disclosed it to Adobe on April 28th, together with two other issues (CVE-2025-54254 and CVE-2025-49533). However, Adobe patched only the latter in April, leaving the other two unfixed for over 90 days, until after the two security researchers published a write-up on July 29th detailing how the vulnerabilities work and how they can be exploited. Adobe finally released security updates on August 9th to address the CVE-2025-54253 vulnerability, confirming that proof-of-concept exploit code was already publicly available. As Searchlight Cyber explained, CVE-2025-54253 is an authentication bypass that leads to remote code execution (RCE) via Struts DevMode. The researchers also advised admins to restrict Internet access to AEM Forms when deployed as a standalone application if they can't immediately patch the software. CISA has now added this vulnerability to its Known Exploited Vulne...
CISA: Maximum-severity Adobe flaw now exploited in attacks
BleepingComputer
·Sergiu Gatlan
·Published Oct 16, 2025
·Updated
Affected Software
1 affected component
Adobe Experience Manager=6.5.23
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a maximum-severity vulnerability in Adobe Experience Manager that is being actively exploited by attackers.
2
What is the severity level of the Adobe vulnerability mentioned?
The vulnerability is categorized as maximum-severity and is tracked as CVE-2025-54253.
3
What type of security issue does this vulnerability allow?
The vulnerability allows attackers to execute code on unpatched systems.
4
Which specific product version of Adobe is affected by this flaw?
The affected product is Adobe Experience Manager version 6.5.23.
5
What agency has issued a warning about this Adobe vulnerability?
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding this vulnerability.