peter bassill · operator
$ cve CVE-2025-49533 JSON

CVE-2025-49533

9.8
CRITICAL · CVSS 3.1 · EPSS 56.1% (pctl 99)

Patch early

EPSS 56.1% — above the 10% action threshold.

Description

Adobe Experience Manager (MS) versions 6.5.23.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction. Scope is unchanged.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS56.05% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2025-07-08
Last modified2026-06-17

Affected (1)

VendorProduct
adobeexperience manager

References

→ the Explorer  ·  watch your stack  ·  NVD