CISA Flags Adobe AEM Flaw with Perfect 10.0 Score — Already Under Active Attack

Based on proof of active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a major security issue affecting Adobe Experience Manager to its list of known exploited vulnerabilities (KEVs).

This vulnerability is a maximum-severity misconfiguration problem called CVE-2025-54253 (CVSS score: 10.0), which has the potential to cause arbitrary code execution.

The flaw affects Adobe Experience Manager (AEM) Forms on JEE versions 6.5.23.0 and below, according to Adobe. Version 6.5.0-0108, which was made available in early August 2025, addressed it along with CVE-2025-54254 (CVSS score: 8.6).

According to security firm FireCompass, the vulnerability arises from the potentially vulnerable /adminui/debug servlet, which interprets user-supplied OGNL expressions as Java code without the need for input validation read more about CISA Flags Adobe AEM Flaw with Perfect 10.0 Score Already Under Active Attack.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *