VDB
CVE-2025-64610
CVE-2025-64610
PUBLISHED
CVSS 5.400000095367432 MEDIUM
Adobe has released a security update for Adobe Experience Manager (AEM). This update addresses important and moderate vulnerabilities that could result in privilege escalation, security feature bypass, and arbitrary code execution. Adobe is not aware of any exploits in the wild for any of the issues addressed in this update. Vulnerability: Cross-site Scripting (Stored XSS) (CWE-79) Impact: Arbitrary code execution Severity: Important CVSS: 5.4 CWE: CWE-79
EPSS 0.28% · 18.3th percentile
Risk Scores
CVSS 3.1
5.400000095367432
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS Score
0.28%
18.3th percentile
Timeline
- Dec 9, 2025 CVE Published
- Mar 17, 2026 Security Advisory
- Mar 17, 2026 Security Advisory
- Sep 8, 2026 CVE Updated
- Sep 9, 2026 EPSS Score
- Sep 12, 2026 EPSS Score
- Sep 17, 2026 EPSS Score
- Sep 18, 2026 EPSS Score
- Sep 24, 2026 EPSS Score
- Sep 26, 2026 EPSS Score
- Sep 30, 2026 EPSS Score
- Oct 3, 2026 EPSS Score
References
- https://helpx.adobe.com/security/products/experience-manager/apsb25-115.html advisory
- https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-64610 advisory
- https://experienceleague.adobe.com/en/docs/experience-manager-cloud-service/content/release-notes/release-notes/release-notes-current patch