CVE-2025-64537
Adobe has fixed multiple vulnerabilities in Adobe Experience Manager. The vulnerabilities in Adobe Experience Manager include, among others, the lack of authentication on a critical function, allowing unauthorized write actions without user interaction. Additionally, there is a Server-Side Request Forgery (SSRF) vulnerability that allows an attacker with low privileges to execute arbitrary code on the server and gain access to accounts or sessions. Furthermore, there are multiple Cross-Site Scripting (XSS) vulnerabilities, both stored and DOM-based, that allow attackers to inject and execute malicious JavaScript code in users' browsers, potentially leading to session hijacking and unauthorized actions. There is also a Path Traversal vulnerability that allows reading files outside the intended directory structure without user interaction. Additionally, there is an XML External Entity (XXE) vulnerability that allows the execution of arbitrary code, access to sensitive files, and privilege escalation without user interaction. These vulnerabilities affect the confidentiality, integrity, and availability of systems running Adobe Experience Manager.
CSIRTS triage
- What
- Multiple vulnerabilities allow unauthorized actions and access to sensitive data.
- Who is affected
- Users of Adobe Experience Manager.
- Urgency
- Remediation is critical due to the potential for exploitation and data breaches.
- Action
- Users should update to the latest version of Adobe Experience Manager.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2025-64537
Get an email if CVE-2025-64537 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.73% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 51% of all EPSS-scored CVEs.
Advisory coverage (1)
- unknownNCSC-2026-0246 [1.00] [M/H] Vulnerabilities fixed in Adobe Experience Managerncsc-nl · 2026-07-17
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2025-64537)