This Adobe AEM flaw is as dangerous as they come, and it’s already being exploited


  • Adobe has fixed two critical AEM bugs that allow code execution and file access without user interaction
  • CISA added CVE-2025-54253 and CVE-2025-54254 to KEV, confirming active exploitation
  • Agencies must patch by Nov. 5; private sector is encouraged to follow due to widespread risk

Adobe recently fixed two bugs in their Experience Manager product, including a maximum severity one that allows malicious actors to execute arbitrary code.

While the company said it is “not aware” of in-the-wild exploits, it said it saw proof-of-concept (PoC) exploits out there. Also, the US Cybersecurity and Infrastructure Security Agency (CISA) added it to the KEV (Known Exploited Vulnerabilities Catalog), which means it is being used in attacks.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top