CVE-2026-75745

10.0

Adobe · AEM 6.5 Forms JEE

Adobe AEM 6.5 Forms JEE is vulnerable to an incorrect authorization flaw allowing unauthenticated attackers to achieve arbitrary remote code execution with changed scope.

Executive summary

A critical authorization vulnerability in Adobe AEM 6.5 Forms JEE enables unauthenticated remote code execution, posing a severe risk to system integrity and confidentiality.

Vulnerability

This vulnerability is an incorrect authorization flaw (CWE-863) that allows an unauthenticated attacker to execute arbitrary code on the target system. The exploit requires no user interaction and operates with a changed scope, significantly increasing the potential impact of the attack.

Business impact

The CVSS score of 10.0 reflects the critical nature of this vulnerability, indicating that successful exploitation can lead to a complete compromise of the affected server. Potential consequences include unauthorized access to sensitive form data, full system takeover, and lateral movement within the network. Such a breach could result in significant operational disruption, regulatory noncompliance, and long term reputational damage.

Remediation

Immediate Action: Administrators must update Adobe AEM 6.5 Forms JEE to version 6.5.25 (applying AEMForms-6.5.0-0134 Hotfix) or upgrade to 6.5 LTS SP3 to resolve the vulnerability.

Proactive Monitoring: Security teams should monitor system logs for suspicious process execution, unexpected outbound network connections from the AEM server, and unauthorized administrative access attempts.

Compensating Controls: Deploy Web Application Firewall (WAF) rules designed to detect and block malicious payloads directed at AEM endpoints as a temporary measure while patch deployment is finalized.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical severity of this flaw and the potential for full system compromise, immediate remediation is required. Organizations should prioritize patching their AEM environments as soon as the vendor updates are available to eliminate this exposure. Failure to act promptly leaves the infrastructure vulnerable to trivial remote exploitation.

More Adobe CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources