VDB
CVE-2025-54253
CVE-2025-54253
PUBLISHED
KEV
CVSS 10 CRITICAL
Adobe has released a security update for Adobe Experience Manager Forms on Java Enterprise Edition (JEE). This update addresses critical vulnerabilities that could lead to arbitrary code execution and arbitrary file system read. Adobe is aware that CVE-2025-54253 and CVE-2025-54254 have a publicly available proof-of-concept. Adobe is not aware of these issues being exploited in the wild. Vulnerability: Incorrect Authorization (CWE-863) Impact: Arbitrary code execution Severity: Critical CVSS: 10.0 CWE: CWE-863
EPSS 87.99% · 99.8th percentile
Risk Scores
CVSS 3.1
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score
87.99%
99.8th percentile
Timeline
- Aug 5, 2025 CVE Published
- Aug 5, 2025 PoC Published
- Aug 6, 2025 EPSS Score
- Aug 6, 2025 PoC Published
- Aug 6, 2025 PoC Published
- Aug 6, 2025 PoC Published
- Aug 6, 2025 PoC Published
- Aug 6, 2025 PoC Published
- Aug 6, 2025 PoC Published
- Aug 6, 2025 PoC Published
- Aug 7, 2025 PoC Published
- Aug 7, 2025 PoC Published