A critical vulnerability CVE-2025-54254 has been identified in Adobe Experience Manager (AEM) Forms, in versions 6.5.23 and earlier, where an improper Restriction of XML External Entity References allows attackers to read arbitrary files on the impacted server. Exploitation of this flaw can lead to unauthorized access and compromise of sensitive customer data, posing significant risks to confidentiality and system integrity. Organizations using AEM Forms are strongly advised to review their current deployment and apply the necessary patches to mitigate this risk.
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Affected assets are outlined in this post.
References:

