CVE-2025-54254 is an XML External Entity (XXE) vulnerability in Adobe Experience Manager Forms on JEE versions 6.5.23.0 and earlier. The SecurityCheckHandler processes the EDCSecurity SOAP header with a namespace-aware DOM parser that permits external-entity resolution. A remote attacker can submit crafted XML containing a DOCTYPE and external entity declarations, causing the application to resolve attacker-controlled external entities. The flaw permits unauthenticated retrieval of local filesystem content, including disclosure through SOAP fault responses.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a single Python tool (aempwn.py) plus README and GPLv3 license. The tool is a multi-target network scanner aimed at Adobe Experience Manager (AEM) Forms endpoints for CVE-2025-54253 and CVE-2025-54254. It normalizes targets to HTTPS by default, then POSTs XML to a fixed list of likely AEM Forms submission endpoints. Capabilities include: (1) a safe behavior probe using a per-run canary token to detect XML reflection/unsafe parsing surface; (2) in-band XXE probes attempting to read local files (/etc/hostname, /etc/passwd, C:\\Windows\\win.ini) and AWS metadata via 169.254.169.254; (3) an OOB XXE mode that sends a parameter-entity payload referencing {oob_url}/evil.dtd (requires attacker-hosted DTD and monitoring); and (4) an RCE escalation mode that sends an external entity reference to an attacker-supplied LDAP/JNDI URL (e.g., ldap://host:1389/#Exploit), intended to trigger Java class loading/execution when combined with external LDAP/HTTP infrastructure (as described in README). Results are scored and printed; confirmed hits are appended to an output file (code default: aempwn-results.txt). The code uses threading for mass scanning and disables TLS verification.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated XML external entity vulnerability in Adobe Experience Manager Forms Axis-based web services. Crafted SOAP security headers can resolve external entities, read local files, and disclose their contents in error responses.
An Improper Restriction of XML External Entity Reference vulnerability in Adobe Experience Manager (AEM) Forms on JEE.
Vulnerability in Adobe Experience Manager Forms on JEE involving improper restriction of external references in processed XML documents, enabling XXE attacks and file read access.
A critical misconfiguration vulnerability in Adobe Experience Manager (AEM) Forms on JEE that allows attackers to bypass security mechanisms and execute code on the system.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.