Two Adobe enterprise platforms — Commerce and Magento, and Experience Manager Forms — each produced a confirmed-exploited vulnerability at the very top of the severity scale within days of each other in October 2025, one a CVSS 9.1 session-takeover bug and the other a perfect CVSS 10.0 code execution flaw.
| CVE | CVSS | Product | Added to KEV |
|---|---|---|---|
| CVE-2025-54253 | 10.0 | Experience Manager (AEM) Forms | 15 Oct 2025 |
| CVE-2025-54236 | 9.1 | Commerce and Magento | 24 Oct 2025 |
Why these two findings belong together despite touching different products
Commerce/Magento and Experience Manager Forms serve very different functions — one runs online storefronts, the other builds customer-facing forms and document workflows — but both sit at the center of Adobe's enterprise digital-experience portfolio, both are frequently internet-facing by design, and both produced a critical-severity, no-user-interaction vulnerability confirmed exploited in the same ten-day window. CVE-2025-54253 is described in NVD as a misconfiguration vulnerability that lets an attacker bypass security mechanisms and execute code, with the CVSS vector reflecting a changed scope — meaning the compromise isn't contained to the vulnerable component itself but can reach outside it into connected systems. A perfect 10.0 score combined with a scope change is about as severe as a single vulnerability entry gets.
CVE-2025-54236 targets the Commerce REST API specifically, allowing an attacker to achieve session takeover through improper input validation, again without requiring any user interaction. A customer account takeover vulnerability in a REST API that Commerce and Magento storefronts expose publicly by design is a direct path to fraud, payment data exposure, and reputational damage for any retailer running an affected version — and unlike a purely internal enterprise tool, an e-commerce storefront's attack surface is, by its very business purpose, reachable from the entire internet.
What to check this week
Patch AEM Forms and Commerce/Magento independently and immediately — both CVEs scored at the critical end of the range and both require no user interaction, meaning exploitation can proceed the moment a vulnerable, internet-reachable instance is found.
Audit Commerce REST API exposure and session management specifically, given that CVE-2025-54236's impact is customer account takeover — a class of compromise that customer-facing retailers cannot treat as an abstract risk.
Verify AEM Forms configuration against Adobe's hardening guidance, since NVD characterizes CVE-2025-54253 as a misconfiguration vulnerability, implying that deployment-time configuration choices, not just missing patches, are part of the exposure.
Review any downstream systems connected to AEM Forms for scope-expansion risk — the CVSS vector's changed scope for CVE-2025-54253 means a successful exploit isn't guaranteed to stay contained to the Forms component alone.
Why enterprise platform vulnerabilities carry a different blast radius than endpoint bugs
Commerce, Magento, and Experience Manager Forms are not desktop software running on one employee's laptop — they are shared platforms that process customer transactions, personal data, and form submissions on behalf of an entire organization's public-facing digital presence. A vulnerability in this class of software doesn't compromise one user's session; it compromises the trust relationship between a business and every customer who has ever interacted with that storefront or form. That distinction matters when triaging patch priority: an endpoint bug requiring a user to open a malicious file caps its own blast radius at whoever opens it, while a pre-authentication or no-interaction bug in a shared enterprise platform has no such natural limit.
A closing note on the October 2025 timing
Both vulnerabilities entered CISA's KEV catalogue within the same ten-day window in October 2025, which is either coincidence or evidence that researchers and attackers were independently focused on Adobe's enterprise product lines during that specific period — either way, it's a reminder that KEV additions often cluster in time around a vendor even when the underlying bugs are technically unrelated, and that cluster itself is a signal worth tracking rather than dismissing as noise.
How Safeguard helps
Safeguard's continuous inventory extends visibility to enterprise platforms like Adobe Commerce, Magento, and Experience Manager Forms with the same rigor applied to endpoint software, recognizing that a critical vulnerability in a public-facing storefront or forms platform carries a blast radius that reaches every customer the business serves, not just the server it runs on.