Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Promoting global and environmental health research in Canada

India’s Kuku nabs $85 million as mobile content wars heat up

CISA reports flaw in Adobe AEM with perfect 10.0 score – already under active attack

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » CISA reports flaw in Adobe AEM with perfect 10.0 score – already under active attack
Identity

CISA reports flaw in Adobe AEM with perfect 10.0 score – already under active attack

userBy userOctober 16, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

October 16, 2025Ravi LakshmananVulnerability/Data Security

CISA reports flaw in Adobe AEM

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical security flaw affecting Adobe Experience Manager to its Known Exploited Vulnerabilities (KEV) catalog based on evidence of active exploitation.

The vulnerability in question is CVE-2025-54253 (CVSS score: 10.0), a maximum severity misconfiguration bug that may lead to arbitrary code execution.

According to Adobe, this flaw affects Adobe Experience Manager (AEM) Forms with JEE versions 6.5.23.0 and earlier. This issue was addressed in version 6.5.0-0108, released in early August 2025, along with CVE-2025-54254 (CVSS score: 8.6).

“The flaw results from the compromised exposure of the /adminui/debug servlet that evaluates user-supplied OGNL expressions as Java code, without requiring authentication or input validation,” security firm FireCompass notes. “Exploitation of this endpoint could allow an attacker to execute arbitrary system commands with a single crafted HTTP request.”

CIS build kit

There is currently no publicly available information on how this security flaw is being exploited in real-world attacks, but Adobe acknowledges in the advisory that “CVE-2025-54253 and CVE-2025-54254 have publicly available proofs of concept.”

In view of active abuse, Federal Civilian Executive Branch (FCEB) agencies are encouraged to apply the necessary fixes by November 5, 2025.

This development comes a day after CISA added the SKYSEA Client View Critical Improper Authentication Vulnerability (CVE-2016-7836, CVSS Score: 9.8) to the KEV Catalog. Japan Vulnerability Notes (JVN) stated in an advisory released in late 2016 that “attacks exploiting this vulnerability have been observed in the wild.”

“SKYSEA Client View contains an improper authentication vulnerability that could allow remote code execution due to a flaw in the authentication process in TCP connections with the management console program,” the agency said.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleDiscover Spotify working on ‘SongDNA’ feature to introduce you to the people behind your favorite music
Next Article India’s Kuku nabs $85 million as mobile content wars heat up
user
  • Website

Related Posts

Chinese threat group Jewelbug secretly infiltrated Russian IT networks for months

October 15, 2025

F5 breach exposes BIG-IP source code — state hackers behind massive intrusion

October 15, 2025

The AI Revolution: Beyond Superintelligence – TwinH Leads the Charge in Personalized, Secure Digital Identities

October 15, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Promoting global and environmental health research in Canada

India’s Kuku nabs $85 million as mobile content wars heat up

CISA reports flaw in Adobe AEM with perfect 10.0 score – already under active attack

Discover Spotify working on ‘SongDNA’ feature to introduce you to the people behind your favorite music

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

The AI Revolution: Beyond Superintelligence – TwinH Leads the Charge in Personalized, Secure Digital Identities

Revolutionize Your Workflow: TwinH Automates Tasks Without Your Presence

FySelf’s TwinH Unlocks 6 Vertical Ecosystems: Your Smart Digital Double for Every Aspect of Life

Beyond the Algorithm: How FySelf’s TwinH and Reinforcement Learning are Reshaping Future Education

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.