logo

CISA: Maximum-severity Adobe flaw now exploited in attacks

ID: 1c710294-8de3-564b-8ce7-8a808cc993d6

STIX ID: report--1c710294-8de3-564b-8ce7-8a808cc993d6

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-10-16

Date Updated: 2026-07-17

Author: Sergiu Gatlan

...
...

CISA warns that CVE-2025-54253, a critical authentication-bypass in Adobe Experience Manager (AEM) Forms (JEE ≤ 6.5.23), has been actively exploited to achieve remote code execution; proof-of-concept code was public and Adobe released patches on August 9 after delayed remediation. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog, triggering mandatory patching timelines for federal agencies and urging all organizations to apply mitigations or discontinue use if unable to patch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.