Tech Wavo
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock
Tech Wavo
No Result
View All Result

This Adobe AEM flaw is as dangerous as they come, and it’s already being exploited

Tech Wavo by Tech Wavo
October 16, 2025
in Computers
0




  • Adobe patched two critical AEM flaws enabling code execution and file access without user interaction
  • CISA added CVE-2025-54253 and CVE-2025-54254 to KEV, confirming active exploitation
  • Agencies must patch by November 5; private sector urged to follow due to widespread risk

Adobe recently patched two flaws in its Experience Manager product, including a maximum-severity one that allows malicious actors to execute arbitrary code.

While the company said it is “not aware” of in-the-wild exploits, it did say that it saw proof-of-concept (PoC) exploits out there. Also, US Cybersecurity and Infrastructure Security Agency (CISA) added it to KEV (the known exploited vulnerability catalog), meaning it is being used in attacks.

Adobe Experience Manager (AEM) is Adobe’s enterprise-level content management system (CMS) used for building and managing websites, mobile apps, and digital experiences. It helps large organizations create, organize, and deliver personalized content across different channels.


You may like

Added to CISA’s KEV

The two flaws in question are tracked as CVE-2025-54253 and CVE-2025-54254. The former is described as a “misconfiguration vulnerability” that can be abused to bypass security mechanisms and has a severity score of 10/10 (critical).

The latter is an “improper restriction of XML External Entity Reference (‘XXE)’ vulnerability that results in arbitrary file system read and allows attackers to access sensitive files – without any user interaction. It was given a severity score of 8.6/10 (high).

Both bugs were found in Adobe Experience Manager versions 6.5.23 and earlier. The patch, released in August this year, brings the tool to version 6.5.0-0108.

On October 15, CISA added both flaws to its KEV catalog, confirming reports of abuse in the wild. When a bug is added to KEV, Federal Civilian Executive Branch (FCEB) agencies have a three-week deadline to apply available fixes and mitigations or stop using the vulnerable tools altogether.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

In Adobe’s case, agencies have until November 5, 2025, to apply the patches.

While CISA’s deadline only applies to FCEB agencies, other agencies and businesses in the private sector are advised to follow suit, since cybercriminals rarely differentiate between the two and will target whoever is vulnerable.

Via The Hacker News


Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

You might also like

Previous Post

Windows 10’s final patch fixes a bewildering number of security flaws – and shows why you need extended updates

Next Post

Getac’s new AMD-powered rugged laptop brings wild AI power and eco-friendly design to the toughest industrial missions

Next Post
Getac’s new AMD-powered rugged laptop brings wild AI power and eco-friendly design to the toughest industrial missions

Getac’s new AMD-powered rugged laptop brings wild AI power and eco-friendly design to the toughest industrial missions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

The internet is now mostly written by machines, study finds

by Tech Wavo
October 17, 2025
0
The internet is now mostly written by machines, study finds
Computers

AI now writes the majority of newly published articles online, according to a study from GraphiteDespite the volume, most AI-generated...

Read more

EFF, unions sue Trump administration over alleged mass social media surveillance of legal residents

by Tech Wavo
October 17, 2025
0
EFF, unions sue Trump admin. over alleged mass social media surveillance of legal residents
Computers

Digital rights group the Electronic Frontier Foundation (EFF) filed a lawsuit on Thursday against the Trump administration over the government’s...

Read more

This sleek aluminum workstation folds into your backpack, yet your $10,000 MacBook Pro may not feel safe there

by Tech Wavo
October 17, 2025
0
This sleek aluminum workstation folds into your backpack, yet your $10,000 MacBook Pro may not feel safe there
Computers

A workstation designed for travel still feels risky for expensive laptopsOpen-source customization adds freedom, not necessarily confidence, for mobile creatorsSmart...

Read more

Defunct electric aircraft startup Lilium’s tech lives on over at Archer

by Tech Wavo
October 17, 2025
0
Defunct electric aircraft startup Lilium’s tech lives on over at Archer
Computers

Electric aircraft startup Lilium may have ceased operations a year ago, but its insolvency filing wasn’t quite the end of...

Read more

Site links

  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use
  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use

No Result
View All Result
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock