This Adobe AEM flaw is as dangerous as they come, and it’s already being exploited

zeeforce
3 Min Read




  • Adobe patched two critical AEM flaws enabling code execution and file access without user interaction
  • CISA added CVE-2025-54253 and CVE-2025-54254 to KEV, confirming active exploitation
  • Agencies must patch by November 5; private sector urged to follow due to widespread risk

Adobe recently patched two flaws in its Experience Manager product, including a maximum-severity one that allows malicious actors to execute arbitrary code.

While the company said it is “not aware” of in-the-wild exploits, it did say that it saw proof-of-concept (PoC) exploits out there. Also, US Cybersecurity and Infrastructure Security Agency (CISA) added it to KEV (the known exploited vulnerability catalog), meaning it is being used in attacks.





Source link

Share This Article
Leave a comment
Optimized by Optimole
Verified by MonsterInsights