CISA Flags Adobe AEM Flaw with Perfect 10.0 Score — Already Under Active Attack
Based on proof of active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a major security issue affecting Adobe Experience Manager to its list of known exploited vulnerabilities (KEVs).
This vulnerability is a maximum-severity misconfiguration problem called CVE-2025-54253 (CVSS score: 10.0), which has the potential to cause arbitrary code execution.
The flaw affects Adobe Experience Manager (AEM) Forms on JEE versions 6.5.23.0 and below, according to Adobe. Version 6.5.0-0108, which was made available in early August 2025, addressed it along with CVE-2025-54254 (CVSS score: 8.6).
According to security firm FireCompass, the vulnerability arises from the potentially vulnerable /adminui/debug servlet, which interprets user-supplied ...





