Executive Summary
In August 2026, Adobe released emergency patches addressing multiple critical vulnerabilities in Adobe Experience Manager (AEM) Forms on JEE, specifically CVE-2025-54253 (Remote Code Execution via Struts DevMode) and CVE-2025-54254 (XML External Entity Injection). These flaws enable unauthenticated attackers to execute arbitrary code or exfiltrate sensitive files from vulnerable servers. CISA has confirmed active exploitation of CVE-2025-54253 as of October 15, 2026. Public proof-of-concept code is available, and exploitation in the wild has been observed. Organizations using AEM Forms are at high risk and must prioritize patching, network hardening, and incident response.
Technical Information
CVE-2025-54253 is a critical remote code execution vulnerability in AEM Forms on JEE, affecting versions up to 6.5.23.0. The flaw arises from a misconfiguration where the com.adobe.framework.SecurityFilter allows requests containing "login", "timeout", or "fail" to bypass authentication controls on /adminui endpoints. Compounding this, Struts2 DevMode is enabled, exposing a debug command interface that accepts OGNL expressions. Attackers can exploit this to execute arbitrary code on the server, leveraging public sandbox bypasses for Struts OGNL injection. The attack is pre-authentication and trivial to automate, making it highly attractive for mass exploitation.
CVE-2025-54254 is an XML External Entity (XXE) injection vulnerability in the Axis-based web services of AEM Forms. The SecurityCheckHandler class parses the EDCSecurity SOAP header without disabling external entity resolution. An attacker can send a crafted SOAP request with a malicious DOCTYPE, causing the server to fetch external DTDs and leak local files (such as /etc/passwd or C:\Windows\win.ini) via HTTP responses. This vulnerability is also pre-authentication and can be exploited for blind XXE via out-of-band (OOB) HTTP requests.
Both vulnerabilities are exacerbated in standalone deployments, especially those running on JBoss. Attackers can chain these flaws with insecure deserialization (previously patched as CVE-2025-49533) for deeper compromise. Public PoC tools, such as AEMPWN and marshalsec, automate detection and exploitation, lowering the barrier for threat actors.
Exploitation in the Wild
CISA has confirmed active exploitation of CVE-2025-54253 as of October 15, 2026. Public PoC code is available on GitHub, and multiple security researchers have demonstrated full attack chains. Exploitation techniques observed include OGNL injection via Struts2 DevMode for direct command execution, blind XXE via OOB HTTP/LDAP requests, and JNDI injection for remote code execution using malicious Java classes. Attackers have been observed exfiltrating sensitive files, establishing reverse shells, and creating persistence artifacts such as /tmp/pwned. Access logs often reveal unauthenticated requests to /adminui or /edcws endpoints, and outbound connections to attacker-controlled infrastructure.
APT Groups using this vulnerability
As of this report, there is no public attribution to specific APT groups exploiting these vulnerabilities. However, the presence of public PoC code and the critical, pre-authentication nature of the flaws make them highly attractive to both financially motivated cybercriminals and state-sponsored actors. Sectors at risk include government, finance, healthcare, and large enterprises globally.
Affected Product Versions
The affected product is Adobe Experience Manager (AEM) Forms on JEE, specifically all versions up to and including 6.5.23.0. This includes all minor and service pack releases up to 6.5.23.0. No evidence was found that Adobe Connect is affected by these specific CVEs in any public advisories or technical write-ups as of this report. All references and advisories point to AEM Forms on JEE as the affected product.
Workaround and Mitigation
Organizations must immediately apply the latest Adobe security updates for AEM Forms as detailed in APSB26-82. Network exposure of AEM Forms should be restricted, especially for standalone deployments, limiting access to internal users and networks only. Administrators should monitor logs for suspicious outbound connections and unauthenticated access to sensitive endpoints. If exploitation is suspected, affected systems should be isolated and subjected to forensic analysis for evidence of remote code execution or data exfiltration. Disabling Struts2 DevMode and reviewing authentication filter configurations are also recommended as defense-in-depth measures.
Indicators of Compromise
The following indicators are point-in-time and should be validated before enforcement in your environment. They are extracted from public research and advisories and are defanged for safe publication.
Type | Indicator | Reported (date) | Source
|
Domain | www[.]slcyber[.]io | 2026-07-29 | https://www.slcyber.io/research/struts-devmode-in-2026-critical-pre-auth-vulnerabilities-in-adobe-experience-manager-forms |
URL | hxxps://www[.]slcyber[.]io/research/struts-devmode-in-2026-critical-pre-auth-vulnerabilities-in-adobe-experience-manager-forms | 2026-07-29 | https://www.slcyber.io/research/struts-devmode-in-2026-critical-pre-auth-vulnerabilities-in-adobe-experience-manager-forms |
References
- SLCyber Research
- GitHub PoC: AEMPWN
- ZeroPath Blog
- HelpNetSecurity
- CVE-2025-54253 Record
- CVE-2025-54254 Record
- IONIX Blog
Rescana is here for you
Rescana empowers organizations to manage third-party risk and supply chain security with our advanced TPRM platform, providing continuous monitoring, automated risk assessment, and actionable intelligence. We are committed to helping you stay ahead of emerging threats and regulatory requirements. For any questions or further assistance, please contact us at info@rescana.com.



