Critical Adobe AEM Vulnerability Exploited: CISA Warns Users

Adobe Experience Manager AEM Forms CVE-2025-54253 CISA KEV Remote Code Execution Apache Struts Cybersecurity
Edward Zhou
Edward Zhou

CEO & Co-Founder

 
October 17, 2025
2 min read

TL;DR

  • A critical misconfiguration vulnerability (CVE-2025-54253) in Adobe Experience Manager (AEM) Forms on JEE is actively exploited, allowing remote code execution. CISA has added this perfect-score flaw to its KEV catalog. Organizations must upgrade to version 6.5.0-0108 or later to patch this severe security risk.

Adobe Experience Manager Vulnerability Exploited

A misconfiguration vulnerability in Adobe Experience Manager (AEM) Forms on Java Enterprise Edition (JEE), tracked as CVE-2025-54253, is being actively exploited in the wild. The Cybersecurity and Infrastructure Security Agency (CISA) has added this flaw to its Known Exploited Vulnerabilities (KEV) catalog.

Vulnerability Details

  • CVE-2025-54253: A misconfiguration in AEM Forms that leaves Apache Struts "devMode" enabled in the admin UI, combined with an authentication bypass. This allows unauthenticated attackers to run expressions that the Struts framework will evaluate, potentially leading to remote code execution (RCE). The CVSS score is a perfect 10.0, indicating maximum severity.
  • Affected Versions: Adobe Experience Manager (AEM) Forms on JEE versions 6.5.23.0 and earlier.
  • Resolution: Upgrade to version 6.5.0-0108 or later.
  • Reported By: Shubham Shah and Adam Kues of Searchlight Cyber.

Technical Explanation

The vulnerability stems from an exposed /adminui/debug servlet. This servlet evaluates user-supplied OGNL expressions as Java code without requiring authentication or input validation, enabling attackers to execute arbitrary system commands via a crafted HTTP request, according to FireCompass.

Researchers Adam Kues and Shubham Shah at Searchlight Cyber disclosed the vulnerabilities, including CVE-2025-54254, an XML external entity (XXE) injection within AEM Forms web services.

Remediation

Adobe addressed the vulnerability in August 2025. Users are advised to upgrade to version 6.5.0-0108 or later as soon as possible. CISA has directed Federal Civilian Executive Branch (FCEB) agencies to patch their systems by November 5, 2025.

Edward Zhou
Edward Zhou

CEO & Co-Founder

 

CEO & Co-Founder of Gopher Security, leading the development of Post-Quantum cybersecurity technologies and solutions.

Related News

New U.S. Directive Sets 2030 Deadline for Contractor Transition to Quantum-Resistant Cryptography
post-quantum cryptography standards

New U.S. Directive Sets 2030 Deadline for Contractor Transition to Quantum-Resistant Cryptography

New federal mandate requires contractors to adopt NIST-approved quantum-resistant cryptography by 2030 to combat 'harvest now, decrypt later' cyber threats.

By Alan V Gutnov July 27, 2026 4 min read
common.read_full_article
New Industry Report Outlines Strategic Defense Frameworks Against Harvest Now, Decrypt Later Quantum Threats
harvest now decrypt later

New Industry Report Outlines Strategic Defense Frameworks Against Harvest Now, Decrypt Later Quantum Threats

Learn how 'Harvest Now, Decrypt Later' quantum threats endanger your data. Discover essential NIST post-quantum migration strategies for your enterprise.

By Brandon Woo July 24, 2026 4 min read
common.read_full_article
NIST Finalizes 2026 Technical Requirements for Post-Quantum Cryptographic Infrastructure Migration and Implementation
NIST post-quantum cryptography standards

NIST Finalizes 2026 Technical Requirements for Post-Quantum Cryptographic Infrastructure Migration and Implementation

NIST finalizes 2026 technical requirements for post-quantum cryptographic migration. Learn the key FIPS standards essential for quantum-resistant infrastructure.

By Alan V Gutnov July 23, 2026 5 min read
common.read_full_article
NIST Post-Quantum Cryptography Standards Formally Adopted for Model Context Protocol Infrastructure Deployments
NIST post-quantum cryptography standards

NIST Post-Quantum Cryptography Standards Formally Adopted for Model Context Protocol Infrastructure Deployments

NIST has finalized post-quantum cryptographic standards. Learn how to implement ML-KEM and ML-DSA to secure your Model Context Protocol (MCP) infrastructure.

By Brandon Woo July 22, 2026 5 min read
common.read_full_article