CVE-2025-49533: Adobe Experience Manager

Critical severity, CVSS 9.8. EPSS: 51.7% chance of exploitation in the next 30 days.

Adobe Experience Manager (MS) versions 6.5.23.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction. Scope is unchanged.

Affected products

  • Adobe Experience Manager: up to and including 6.5.23.0

Published 2025-07-08. Last modified 2026-06-17.