CVE-2025-49533 is a critical Deserialization of Untrusted Data vulnerability affecting Adobe Experience Manager versions 6.5.23.0 and earlier, allowing for arbitrary code execution. Rated 9.8 CRITICAL on CVSS, this flaw is remotely exploitable with low complexity, requires no user interaction or privileges, and leads to full system compromise. Exploit code, including Nuclei templates, is publicly available, and the vulnerability is confirmed to be actively exploited in the wild, as indicated by its high EPSS score and significant community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.5.23.0CPE matchmatch criteria | cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.