Adobe has issued urgent release for security updates to address two critical vulnerabilities in Adobe Experience Manager (AEM) Forms on JEE, where 6.5.23.0 and earlier versions were affected. These flaws, identified as CVE-2025-54253 and CVE-2025-54254, have been assigned CVSS base scores of 10.0 and 8.6 respectively, marking them as high-risk threats for enterprise systems. The first vulnerability, CVE-2025-54253, is particularly severe. It stems from misconfigurations in AEM Forms that allow attackers to bypass security controls and execute arbitrary code on affected systems. This exploit does not require any user interaction, impacting the original scope, making it especially dangerous for both internal and internet-facing deployments. Adobe has confirmed that public proof-of-concept (PoC) exploits are available, although no active exploitation has been reported so far. The second flaw, CVE-2025-54254, involves improper handling of XML external entity (XXE) references. This weakness could enable attackers to read sensitive files from the local file system without user involvement. XXE vulnerabilities are commonly used to extract configuration files, credentials, and other confidential data, and may serve as entry points for deeper system compromise. To defend against such critical threats, organizations need to update to AEM Forms on JEE version 6.5.0-0108 or later. The release patches fix the RCE and XXE vulnerabilities significantly reducing the attack surface. If the update is delayed, could cause systems exposure to serious compromise, as PoC code is publicly available.
Security researchers have identified a new variant of the SparkCat malware circulating on both the Apple App Store and Google Play Store, more than a year after its initial discove...
The European Union’s cybersecurity agency, CERT-EU, has attributed a significant cloud breach involving the European Commission to the TeamPCP threat group. The attack targeted t...
Microsoft has rolled out automatic updates for unmanaged Windows 11 24H2 Home and Pro edition devices to Windows 11 25H2, also known as the Windows 11 2025 Update. This transition ...