CVE-2025-54253

CRITICAL KEV

Adobe Experience Manager Forms < 6.5.23.0 - Incorrect Authorization

Title source: rule

Description

Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.

Exploits (5)

github WRITEUP 7 stars
by AdityaBhatt3010 · poc
https://github.com/AdityaBhatt3010/CVE-2025-54253-Inside-the-Adobe-AEM-Forms-Zero-Day
github WORKING POC 2 stars
by adminlove520 · pythonpoc
https://github.com/adminlove520/CVE-Poc_All_in_One/tree/main/2025/CVE-2025-54253
nomisec SCANNER 2 stars
by zoomdbz · poc
https://github.com/zoomdbz/AEMPWN
nomisec SUSPICIOUS 1 stars
by jm7knz · poc
https://github.com/jm7knz/CVE-2025-54253-Exploit-Demo
nomisec WORKING POC 1 stars
by Shivshantp · poc
https://github.com/Shivshantp/CVE-2025-54253-Exploit-Demo

Scores

CVSS v3 10.0
EPSS 0.1971
EPSS Percentile 95.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

CISA KEV 2025-10-15
VulnCheck KEV 2025-08-12
ENISA EUVD EUVD-2025-23647
CWE
CWE-863
Status published
Products (1)
adobe/experience_manager_forms < 6.5.23.0
Published Aug 05, 2025
KEV Added Oct 15, 2025
Tracked Since Feb 18, 2026