VDB

CVE-2025-54253

CVE-2025-54253 PUBLISHED KEV CVSS 10 CRITICAL

Adobe has released a security update for Adobe Experience Manager Forms on Java Enterprise Edition (JEE). This update addresses critical vulnerabilities that could lead to arbitrary code execution and arbitrary file system read. Adobe is aware that CVE-2025-54253 and CVE-2025-54254 have a publicly available proof-of-concept. Adobe is not aware of these issues being exploited in the wild. Vulnerability: Incorrect Authorization (CWE-863) Impact: Arbitrary code execution Severity: Critical CVSS: 10.0 CWE: CWE-863

EPSS 87.99% · 99.8th percentile

Risk Scores

CVSS 3.1
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score
87.99%
99.8th percentile

Timeline

  • Aug 5, 2025 CVE Published
  • Aug 5, 2025 PoC Published
  • Aug 6, 2025 EPSS Score
  • Aug 6, 2025 PoC Published
  • Aug 6, 2025 PoC Published
  • Aug 6, 2025 PoC Published
  • Aug 6, 2025 PoC Published
  • Aug 6, 2025 PoC Published
  • Aug 6, 2025 PoC Published
  • Aug 6, 2025 PoC Published
  • Aug 7, 2025 PoC Published
  • Aug 7, 2025 PoC Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›