A critical security vulnerability, tracked as CVE-2025-54253 with a CVSS score of 10.0, has been identified in Adobe Experience Manager (AEM) Forms on JEE versions 6.5.23.0 and earlier. The flaw is a misconfiguration that exposes the /adminui/debug servlet, which evaluates user-supplied OGNL expressions as Java code without requiring authentication or input validation. This allows attackers to execute arbitrary system commands on affected servers with a single crafted HTTP request, leading to the possibility of full remote code execution. Adobe addressed the vulnerability in version 6.5.0-0108, released in early August 2025, and also patched a related issue, CVE-2025-54254, with a CVSS score of 8.6. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-54253 to its Known Exploited Vulnerabilities (KEV) catalog, confirming evidence of active exploitation in the wild. CISA has issued an emergency alert, urging all Federal Civilian Executive Branch (FCEB) agencies and other organizations to apply the necessary patches by November 5, 2025, to mitigate the risk. Security firm FireCompass highlighted the severity of the flaw, noting that the exposed endpoint can be abused without authentication, making exploitation trivial for attackers. Adobe has acknowledged the existence of a publicly available proof-of-concept for both CVE-2025-54253 and CVE-2025-54254, increasing the urgency for remediation. While specific details of real-world attacks have not been disclosed, the active exploitation status underscores the immediate threat to organizations running vulnerable AEM instances. The vulnerability's critical nature is amplified by its potential to allow attackers to gain complete control over affected systems. Organizations are strongly advised to review their deployments and ensure all relevant patches are applied without delay. The exposure of such a high-impact endpoint in a widely used enterprise content management platform raises significant concerns for both public and private sector entities. The incident demonstrates the ongoing risk posed by misconfigurations and insufficient input validation in complex web applications. Security teams should also review access logs for signs of exploitation attempts and consider additional monitoring of AEM endpoints. The rapid response from CISA and Adobe highlights the importance of coordinated vulnerability disclosure and mitigation in the face of active threats. Failure to address this vulnerability could result in severe compromise of sensitive data and business operations. The situation remains dynamic, and organizations should stay alert for further advisories or indicators of compromise related to CVE-2025-54253.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
Alongside the KEV listing, CISA required Federal Civilian Executive Branch agencies to fix or mitigate CVE-2025-54253 by November 5, 2025. The directive was issued to reduce exposure to ongoing exploitation of the Adobe flaw.
On October 16, 2025, CISA added Adobe Experience Manager Forms flaw CVE-2025-54253 to its Known Exploited Vulnerabilities catalog after confirming in-the-wild exploitation. The agency highlighted the bug's maximum 10.0 CVSS score and its impact on AEM Forms on JEE deployments.
Adobe issued fixes in August 2025 for the AEM Forms on JEE vulnerabilities, including CVE-2025-54253, a misconfiguration issue that can enable unauthenticated remote code execution. The updates addressed affected versions 6.5.23.0 and earlier.
Security researchers Shubham Shah and Adam Kues reported CVE-2025-54253 and CVE-2025-54254 in Adobe Experience Manager Forms. After Adobe did not patch within 90 days, they published proof-of-concept exploit code, increasing the risk of real-world abuse.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
8 references tracked. Mallory keeps watching after this page renders.
thecyberexpress.com
Open sourcescworld.com
Open sourcesocradar.io
Open sourcesecurityaffairs.com
Open sourcesecurityonline.info
Open sourcehelpnetsecurity.com
Open sourcethehackernews.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.