Junglewise Threat Intelligence

CVE-2025-54253: Adobe Experience Manager Forms remote code execution

CVE-2025-54253 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2025-10-15

Vendors: Adobe.

Executive brief

Adobe Experience Manager Forms, a platform used by organizations to create and manage digital forms and documents, contains a critical security flaw. This vulnerability allows an unauthenticated attacker to remotely execute commands on the server, potentially leading to a full system takeover and theft of sensitive data. This issue is currently being exploited in the wild, making immediate patching essential to protect corporate infrastructure.

Technical details

Adobe Experience Manager (AEM) Forms versions 6.5.23 and earlier are vulnerable to a critical misconfiguration (CWE-16/CWE-863) that results in unauthenticated remote code execution (RCE). The vulnerability stems from an incorrect authorization check or misconfiguration, potentially related to Struts 'devMode' being enabled in the JEE environment. An attacker can exploit this over the network without any user interaction to bypass security mechanisms and execute arbitrary code with the privileges of the application. The vulnerability has a CVSS 3.1 score of 10.0 and is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Affected products

  • Adobe Experience Manager Forms 6.5.23 and earlier

Timeline

  • 2025-08-05: disclosed: Initial CVE publication
  • 2025-10-15: kev added: CISA added to Known Exploited Vulnerabilities catalog
  • 2025-10-15: exploited: Confirmed active exploitation in the wild