Adobe released security updates for Adobe Experience Manager (AEM) Forms on JEE to fix two critical vulnerabilities, including CVE-2025-54253, a CVSS 10.0 flaw that can allow unauthenticated remote code execution. The issue affects AEM Forms on JEE versions earlier than 6.5.0-0108 and stems from the Apache Struts developer mode debug servlet being exposed at /adminui/debug without authentication, allowing attacker-controlled OGNL expressions to be evaluated. Adobe’s bulletin and follow-on reporting also identified CVE-2025-54254, a CVSS 8.6 XML External Entity (XXE) vulnerability that could expose sensitive data and contribute to full system compromise.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
A Rapid7 Metasploit pull request added an exploit module for CVE-2025-54253 targeting Adobe AEM Forms on JEE. The module exploits the exposed Struts devMode debug servlet at /adminui/debug to achieve unauthenticated remote code execution via attacker-controlled OGNL expressions.
CSIRT.SK reported that proof-of-concept exploit code was publicly available for the Adobe Experience Manager Forms on JEE vulnerabilities, increasing the urgency of patching. The report also described CVE-2025-54253 as a devMode OGNL injection issue and CVE-2025-54254 as an XXE flaw.
Adobe published APSB25-82 security updates for Adobe Experience Manager Forms on JEE to address two critical vulnerabilities, including CVE-2025-54253 and CVE-2025-54254. CSIRT.SK reports the fixes apply to versions earlier than 6.5.0-0108 and urges administrators to update immediately.
Searchlight Cyber disclosed three critical standalone AEM Forms vulnerabilities to Adobe, including CVE-2025-49533, an insecure Java deserialization issue in GetDocumentServlet that permits remote command execution. The disclosure also covered the Struts DevMode RCE and unauthenticated XXE issues later assigned CVE-2025-54253 and CVE-2025-54254.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourceslcyber.io
Open sourcecsirt.sk
Open sourcehelpx.adobe.com
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.