CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2025-64538

unknowncovered by 1 sourcefirst seen 2026-07-17
Adobe has fixed multiple vulnerabilities in Adobe Experience Manager. The vulnerabilities in Adobe Experience Manager include, among others, the lack of authentication on a critical function, allowing unauthorized write actions without user interaction. Additionally, there is a Server-Side Request Forgery (SSRF) vulnerability that allows an attacker with low privileges to execute arbitrary code on the server and gain access to accounts or sessions. Furthermore, there are multiple Cross-Site Scripting (XSS) vulnerabilities, both stored and DOM-based, that allow attackers to inject and execute malicious JavaScript code in users' browsers, potentially leading to session hijacking and unauthorized actions. There is also a Path Traversal vulnerability that allows reading files outside the intended directory structure without user interaction. Additionally, there is an XML External Entity (XXE) vulnerability that allows the execution of arbitrary code, access to sensitive files, and privilege escalation without user interaction. These vulnerabilities affect the confidentiality, integrity, and availability of systems running Adobe Experience Manager.

CSIRTS triage

What
Multiple vulnerabilities allow unauthorized actions and access to sensitive data.
Who is affected
Users of Adobe Experience Manager.
Urgency
Remediation is critical due to the potential for exploitation and data breaches.
Action
Users should update to the latest version of Adobe Experience Manager.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2025-64538

Get an email if CVE-2025-64538 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2025-64538

CVE.org record

Embed the live status

CVE-2025-64538 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2025-64538 status](https://www.csirts.com/badge/CVE-2025-64538)](https://www.csirts.com/cve/CVE-2025-64538)