Critical severity9.8NVD Advisory· Published Jan 13, 2022· Updated Jun 17, 2026
CVE-2021-40722
CVE-2021-40722
Description
AEM Forms Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by an XML External Entity (XXE) injection vulnerability that could be abused by an attacker to achieve RCE.
Affected products
4cpe:2.3:a:adobe:experience_manager:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:adobe:experience_manager:*:*:*:*:*:*:*:*range: <=6.5.10.0
- (no CPE)range: unspecified
- cpe:2.3:a:adobe:experience_manager_cloud_service:-:*:*:*:*:*:*:*
- Range: <=6.5.10.0
Patches
Vulnerability mechanics
References
1- helpx.adobe.com/security/products/experience-manager/apsb21-103.htmlnvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.