Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-54253

96
FAUCET Score

CVE-2025-54253 is a critical misconfiguration vulnerability affecting Adobe Experience Manager versions 6.5.23 and earlier, specifically within the AEM Forms component. This flaw allows an unauthenticated attacker to bypass security mechanisms and achieve arbitrary code execution without user interaction, with a changed scope. Rated 10.0 CVSS, it poses a severe risk due to its network-based attack vector and high impact on confidentiality, integrity, and availability. The vulnerability is actively exploited in the wild, as confirmed by CISA, and has garnered significant community discussion and media coverage, despite no public exploit code being available on platforms like Metasploit or ExploitDB.

Impacted Technologies

VendorProductVersion(s)CPE
<= 6.5.23.0CPE matchmatch criteria
cpe:2.3:a:adobe:experience_manager_forms:*:*:*:*:*:*:*:*
>= 0, <= 6.5.23CPE match
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*

CVSS Data

CVSS version used by this source: 3.1

10.0CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
87.52%
Probability of exploitation in next 30 days
EPSS Percentile
99.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Added to KEV · Oct 15, 2025
This CVE's current EPSS score of 0.8751 is in the 99th percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

adobevendor investigatingvia nvd_reference
View patch

References

slcyber.io / assetnote-security-research-center/struts-devmode-in-2025-critical-pre-auth-vulnerabilities-in-adobe-experience-manager-forms
ExploitThird Party Advisory
cisa.gov / known-exploited-vulnerabilities-catalog
Third Party AdvisoryUS Government Resource
helpx.adobe.com / security/products/aem-forms/apsb25-82.html
Vendor Advisory