This Adobe AEM flaw is as dangerous as it gets and it’s already being exploited


  • Adobe fixed two critical AEM flaws allowing code execution and file access without user interaction
  • CISA added CVE-2025-54253 and CVE-2025-54254 to KEV, confirming active exploitation
  • Agencies must update the patch by November 5; the private sector is urged to follow due to widespread risk

Adobe recently fixed two vulnerabilities in its Experience Manager product, including one of maximum severity that allows malicious actors to execute arbitrary code.

Although the company said it was “not aware” of exploits in the wild, it said it had seen proof-of-concept (PoC) exploits. Additionally, the US Cybersecurity and Infrastructure Security Agency (CISA) added it to the KEV (the Catalog of Known Exploited Vulnerabilities), meaning it is used in attacks.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top