Back to News & Press

Press Release

Searchlight Cyber Finds Further Critical Vulnerabilities in Adobe Experience Manager

Share on social

July 29, 2025

Lorem ipsum

Table of contents

Share on social

Join the newsletter
Searchlight Cyber Finds Further Critical Vulnerabilities in Adobe Experience Manager

Three new critical vulnerabilities include two paths to RCE and a pre-authentication XXE

Brisbane, Australia, July 29, 2025

The Assetnote Security Research Team at Searchlight Cyber has published the details of three critical vulnerabilities it has discovered in Adobe Experience Manager (AEM) Forms. The researchers disclosed to Adobe that Remote Code Execution (RCE) could be achieved in two different ways on the application, as well as an External Entity Injection (XXE) that does not require authentication to execute. The three new vulnerabilities follow three cross-site scripting vulnerabilities in AEM that the security researchers publicly disclosed earlier in July.

Many large enterprises use the AEM Content Management System to manage their websites, and the Forms function is used for dynamic form components that accept customer input. In total, the Assetnote Security Research Team disclosed three critical vulnerabilities in AEM Forms:

  • Insecure deserialization vulnerability leading to RCE (CVE-2025-49533) - This vulnerability has a CVSS of 9.8. Adobe has provided mitigation advice for customers here.
  • XXE within AEM Forms web services - This vulnerability is exploitable without authentication, making it particularly high risk for AEM Forms customers.
  • Authentication bypass to RCE chain via Struts2 Devmode - Enabling Struts2 Devmode in the application can lead to command execution.

Shubham Shah, SVP of Research and Engineering at Searchlight Cyber commented: “The vulnerabilities we’ve disclosed in AEM Forms are not complex. Given the numerous bugs we’ve discovered and the lack of patches for the XXE and authentication bypass vulnerabilities leading to a RCE chain, we strongly recommend that customers using AEM Forms in standalone mode restrict access to this application to internal users and disable access from the external internet.”

Searchlight Cyber’s security research team continues to perform novel zero-day and N-day security research to ensure maximum coverage and care for its customers’ attack surfaces. All research is integrated into its Attack Surface Management platform, Assetnote, which continuously monitors, detects, and proves the exploitability of exposures before threat actors can use them.

ENDS

About Searchlight Cyber

Searchlight Cyber was founded in 2017 with a mission to stop threat actors from acting with impunity. Its External Cyber Risk Management Platform helps organizations to identify and protect themselves from emerging cybercriminal threats with Attack Surface Management and Threat Intelligence tools designed to separate the signal from the noise. Find out more at www.slcyber.io.

Related Press Releases

Searchlight Cyber Launches Preemptive Threat Exposure Management Platform to Help Organizations Outpace AI-Accelerated Attacks

Press Release

Read press release

August 12, 2026

Searchlight Cyber Launches Preemptive Threat Exposure Management Platform to Help Organizations Outpace AI-Accelerated Attacks

Searchlight Cyber Appoints Paul Ciesielski as Chief Revenue Officer

Press Release

Read press release

June 11, 2026

Searchlight Cyber Appoints Paul Ciesielski as Chief Revenue Officer

Searchlight Cyber Named a Finalist at the 2026 Cyber Risk Awards

Press Release

Read press release

April 27, 2026

Searchlight Cyber Named a Finalist at the 2026 Cyber Risk Awards

Searchlight Cyber Report: Ransomware Groups Claimed Record Number of Victims in 2025 with 30% Annual Increase

Press Release

Read press release

February 17, 2026

Searchlight Cyber Report: Ransomware Groups Claimed Record Number of Victims in 2025 with 30% Annual Increase

Searchlight Cyber Appoints Michael Gianarakis as CEO

Press Release

Read press release

February 4, 2026

Searchlight Cyber Appoints Michael Gianarakis as CEO

Searchlight Cyber Launches Ransomware File Explorer to Enable Pre-Emptive Detection of Leaked Data

Press Release

Read press release

January 22, 2026

Searchlight Cyber Launches Ransomware File Explorer to Enable Pre-Emptive Detection of Leaked Data

Never miss a beat

Get all news and updates about Searchlight Cyber, directly in your inbox.

Subscribe
Please enter a valid email address.
Background Gradient