CVE-2025-54253 is a critical misconfiguration vulnerability affecting Adobe Experience Manager versions 6.5.23 and earlier, specifically within the AEM Forms component. This flaw allows an unauthenticated attacker to bypass security mechanisms and achieve arbitrary code execution without user interaction, with a changed scope. Rated 10.0 CVSS, it poses a severe risk due to its network-based attack vector and high impact on confidentiality, integrity, and availability. The vulnerability is actively exploited in the wild, as confirmed by CISA, and has garnered significant community discussion and media coverage, despite no public exploit code being available on platforms like Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.5.23.0CPE matchmatch criteria | cpe:2.3:a:adobe:experience_manager_forms:*:*:*:*:*:*:*:* | ||
>= 0, <= 6.5.23CPE match | cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.