CISA Flags Adobe AEM Flaw with Perfect 10.0 Score — Already Under Active Attack
好的,我现在需要帮用户总结一篇关于数据安全的文章,控制在100字以内。首先,我得仔细阅读文章内容,抓住关键点。 文章主要讲的是美国网络安全和基础设施安全局(CISA)将Adobe Experience Manager的一个严重漏洞加入到已知被利用的漏洞目录中。这个漏洞CVE-2025-54253的CVSS评分是10.0,属于最高级别的配置错误,可能导致任意代码执行。影响的是AEM Forms on JEE的旧版本,已经修复了。 漏洞的原因是/adminui/debug这个servlet暴露,允许未经身份验证的攻击者执行系统命令。虽然目前没有公开的攻击信息,但有概念验证存在。CISA建议联邦机构在11月5日前修复。 另外,CISA还添加了SKYSEA Client View的一个认证漏洞CVE-2016-7836,CVSS评分9.8,已被野利用。 总结时要包括CISA添加两个高危漏洞到目录中,涉及Adobe和SKYSEA产品,以及修复建议。控制在100字以内,不需要开头语。 </think> 美国网络安全机构将Adobe Experience Manager和SKYSEA Client View的两个高危漏洞加入已知被利用目录中。Adobe漏洞CVE-2025-54253可致任意代码执行,SKYSEA漏洞CVE-2016-7836允许远程代码执行。建议相关机构尽快修复以应对活跃攻击。 2025-10-16 04:26:0 Author: thehackernews.com(查看原文) 阅读量:8 收藏

Vulnerability / Data Security

CISA Flags Adobe AEM Flaw

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical security flaw impacting Adobe Experience Manager to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.

The vulnerability in question is CVE-2025-54253 (CVSS score: 10.0), a maximum-severity misconfiguration bug that could result in arbitrary code execution.

According to Adobe, the shortcoming impacts Adobe Experience Manager (AEM) Forms on JEE versions 6.5.23.0 and earlier. It was addressed in version 6.5.0-0108 released early August 2025, alongside CVE-2025-54254 (CVSS score: 8.6).

The flaw results from the dangerously exposed /adminui/debug servlet, which evaluates user-supplied OGNL expressions as Java code without requiring authentication or input validation," security company FireCompass noted. "The endpoint's misuse enables attackers to execute arbitrary system commands with a single crafted HTTP request."

CIS Build Kits

There is currently no information publicly available on how the security flaw is being exploited in real-world attacks, although Adobe acknowledged in its advisory that "CVE-2025-54253 and CVE-2025-54254 have a publicly available proof-of-concept."

In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are advised to apply the necessary fixes by November 5, 2025.

The development comes a day after CISA also added a critical improper authentication vulnerability in SKYSEA Client View (CVE-2016-7836, CVSS score: 9.8) to the KEV catalog. Japan Vulnerability Notes (JVN), in an advisory released in late 2016, said "attacks exploiting this vulnerability have been observed in the wild."

"SKYSEA Client View contains an improper authentication vulnerability that allows remote code execution via a flaw in processing authentication on the TCP connection with the management console program," the agency said.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


文章来源: https://thehackernews.com/2025/10/cisa-flags-adobe-aem-flaw-with-perfect.html
如有侵权请联系:admin#unsafe.sh