Critical severity9.8NVD Advisory· Published Jul 8, 2025· Updated Jun 17, 2026
CVE-2025-49533
CVE-2025-49533
Description
Adobe Experience Manager (MS) versions 6.5.23.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction. Scope is unchanged.
Affected products
3cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*+ 2 more
- cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*range: <=6.5.23.0
- (no CPE)range: <=6.5.23.0
- (no CPE)range: 0
Patches
Vulnerability mechanics
References
1- helpx.adobe.com/security/products/aem-forms/apsb25-67.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.