CVE-2025-49533
CVE-2025-49533 is a critical-severity vulnerability in Adobe Experience Manager with a CVSS 3.x base score of 9.8. Its EPSS exploit-prediction score of 52% places it in the 99th percentile, indicating an elevated likelihood of exploitation. The underlying weakness is classified as CWE-502.
Key facts
- Severity: Critical (CVSS 3.x base score 9.8)
- EPSS exploit prediction: 52% (99th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2025-20752
- Weakness: CWE-502
- Affected product: Adobe Experience Manager
- Published:
- Last modified:
Description
Adobe Experience Manager (MS) versions 6.5.23.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction. Scope is unchanged.
Frequently asked questions
- What is CVE-2025-49533?
- Adobe Experience Manager (MS) versions 6.5.23.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction. Scope is unchanged.
- How severe is CVE-2025-49533?
- CVE-2025-49533 has a CVSS 3.x base score of 9.8, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2025-49533 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 52% (99th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2025-49533?
- CVE-2025-49533 affects Adobe Experience Manager. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2025-49533?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- Does CVE-2025-49533 have an EU (EUVD) identifier?
- Yes. CVE-2025-49533 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2025-20752.
- When was CVE-2025-49533 published?
- CVE-2025-49533 was published on 2025-07-08 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
More vulnerabilities in Adobe Experience Manager
- CVE-2021-40722 — Critical (CVSS 9.8): AEM Forms Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by an XML External Entity (XXE)…
- CVE-2019-8088 — Critical (CVSS 9.8): Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a command injection vulnerability. Successful exploitation…
- CVE-2019-7964 — Critical (CVSS 9.8): Adobe Experience Manager versions 6.5, and 6.4 have an authentication bypass vulnerability. Successful exploitation…
- CVE-2017-3108 — Critical (CVSS 9.8): Adobe Experience Manager 6.2 and earlier has a malicious file execution vulnerability.
- CVE-2026-48359 — Critical (CVSS 9.6): Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability…
- CVE-2026-48259 — Critical (CVSS 9.6): Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in…
All CVEs affecting Adobe Experience Manager →
Other CWE-502 (Deserialization of Untrusted Data) vulnerabilities
- CVE-2026-69836 — Critical (CVSS 10.0): Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
- CVE-2026-17061 — Critical (CVSS 10.0): A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release…
- CVE-2026-11756 — Critical (CVSS 10.0): A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release…
- CVE-2026-41104 — Critical (CVSS 10.0): Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose…
- CVE-2026-43633 — Critical (CVSS 10.0): HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused by a…
- CVE-2026-33819 — Critical (CVSS 10.0): Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.
Browse all CWE-502 (Deserialization of Untrusted Data) vulnerabilities →