CVE-2025-54253
CRITICAL KEVAdobe Experience Manager Forms < 6.5.23.0 - Incorrect Authorization
Title source: ruleDescription
Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.
Exploits (5)
github
WRITEUP
7 stars
by AdityaBhatt3010 · poc
https://github.com/AdityaBhatt3010/CVE-2025-54253-Inside-the-Adobe-AEM-Forms-Zero-Day
github
WORKING POC
2 stars
by adminlove520 · pythonpoc
https://github.com/adminlove520/CVE-Poc_All_in_One/tree/main/2025/CVE-2025-54253
nomisec
WORKING POC
1 stars
by Shivshantp · poc
https://github.com/Shivshantp/CVE-2025-54253-Exploit-Demo
References (3)
Scores
CVSS v3
10.0
EPSS
0.1971
EPSS Percentile
95.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Details
CISA KEV
2025-10-15
VulnCheck KEV
2025-08-12
ENISA EUVD
EUVD-2025-23647
CWE
CWE-863
Status
published
Products (1)
adobe/experience_manager_forms
< 6.5.23.0
Published
Aug 05, 2025
KEV Added
Oct 15, 2025
Tracked Since
Feb 18, 2026