CVE-2025-54253: Adobe Experience Manager Forms Code Execution Vulnerability

Critical severity, CVSS 10.0. Actively exploited: in CISA KEV since 2025-10-15. EPSS: 88.3% chance of exploitation in the next 30 days.

Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.

Affected products

  • Adobe Experience Manager Forms: up to and including 6.5.23.0

Published 2025-08-05. Last modified 2026-06-17.