Safeguard
Vulnerability Analysis

Adobe Commerce and Experience Manager Forms: Two Critical RCEs in the Same Ten Days

A perfect-10 code execution bug in AEM Forms and a 9.1 session-takeover flaw in Commerce and Magento both entered CISA's KEV catalogue within days of each other in October 2025.

Safeguard Research Team
4 min read

Two Adobe enterprise platforms — Commerce and Magento, and Experience Manager Forms — each produced a confirmed-exploited vulnerability at the very top of the severity scale within days of each other in October 2025, one a CVSS 9.1 session-takeover bug and the other a perfect CVSS 10.0 code execution flaw.

CVECVSSProductAdded to KEV
CVE-2025-5425310.0Experience Manager (AEM) Forms15 Oct 2025
CVE-2025-542369.1Commerce and Magento24 Oct 2025

Why these two findings belong together despite touching different products

Commerce/Magento and Experience Manager Forms serve very different functions — one runs online storefronts, the other builds customer-facing forms and document workflows — but both sit at the center of Adobe's enterprise digital-experience portfolio, both are frequently internet-facing by design, and both produced a critical-severity, no-user-interaction vulnerability confirmed exploited in the same ten-day window. CVE-2025-54253 is described in NVD as a misconfiguration vulnerability that lets an attacker bypass security mechanisms and execute code, with the CVSS vector reflecting a changed scope — meaning the compromise isn't contained to the vulnerable component itself but can reach outside it into connected systems. A perfect 10.0 score combined with a scope change is about as severe as a single vulnerability entry gets.

CVE-2025-54236 targets the Commerce REST API specifically, allowing an attacker to achieve session takeover through improper input validation, again without requiring any user interaction. A customer account takeover vulnerability in a REST API that Commerce and Magento storefronts expose publicly by design is a direct path to fraud, payment data exposure, and reputational damage for any retailer running an affected version — and unlike a purely internal enterprise tool, an e-commerce storefront's attack surface is, by its very business purpose, reachable from the entire internet.

What to check this week

Patch AEM Forms and Commerce/Magento independently and immediately — both CVEs scored at the critical end of the range and both require no user interaction, meaning exploitation can proceed the moment a vulnerable, internet-reachable instance is found.

Audit Commerce REST API exposure and session management specifically, given that CVE-2025-54236's impact is customer account takeover — a class of compromise that customer-facing retailers cannot treat as an abstract risk.

Verify AEM Forms configuration against Adobe's hardening guidance, since NVD characterizes CVE-2025-54253 as a misconfiguration vulnerability, implying that deployment-time configuration choices, not just missing patches, are part of the exposure.

Review any downstream systems connected to AEM Forms for scope-expansion risk — the CVSS vector's changed scope for CVE-2025-54253 means a successful exploit isn't guaranteed to stay contained to the Forms component alone.

Why enterprise platform vulnerabilities carry a different blast radius than endpoint bugs

Commerce, Magento, and Experience Manager Forms are not desktop software running on one employee's laptop — they are shared platforms that process customer transactions, personal data, and form submissions on behalf of an entire organization's public-facing digital presence. A vulnerability in this class of software doesn't compromise one user's session; it compromises the trust relationship between a business and every customer who has ever interacted with that storefront or form. That distinction matters when triaging patch priority: an endpoint bug requiring a user to open a malicious file caps its own blast radius at whoever opens it, while a pre-authentication or no-interaction bug in a shared enterprise platform has no such natural limit.

A closing note on the October 2025 timing

Both vulnerabilities entered CISA's KEV catalogue within the same ten-day window in October 2025, which is either coincidence or evidence that researchers and attackers were independently focused on Adobe's enterprise product lines during that specific period — either way, it's a reminder that KEV additions often cluster in time around a vendor even when the underlying bugs are technically unrelated, and that cluster itself is a signal worth tracking rather than dismissing as noise.

How Safeguard helps

Safeguard's continuous inventory extends visibility to enterprise platforms like Adobe Commerce, Magento, and Experience Manager Forms with the same rigor applied to endpoint software, recognizing that a critical vulnerability in a public-facing storefront or forms platform carries a blast radius that reaches every customer the business serves, not just the server it runs on.

Never miss an update

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.