Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Maximum-severe Adobe flaw now used in attacks
    Security

    Maximum-severe Adobe flaw now used in attacks

    PineapplesUpdateBy PineapplesUpdateOctober 16, 2025No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Maximum-severe Adobe flaw now used in attacks
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Maximum-severe Adobe flaw now used in attacks

    CISA warns that attackers are actively exploiting a maximum-severity vulnerability in Adobe Experience Manager to execute code on unpatched systems.

    tracked as CVE-2025-54253This critical security flaw arises from a misconfiguration vulnerability that affects Adobe Experience Manager (AEM) forms in JEE version 6.5.23 and earlier.

    Successful exploitation could allow unauthenticated threat actors to bypass security mechanisms and remotely execute arbitrary code in low-complexity attacks that do not require user interaction.

    The flaw was discovered by Adam Kues and Shubham Shah of Searchlight Cyber, who disclosed it to Adobe on April 28 along with two other issues (CVE-2025-54254 and CVE-2025-49533).

    However, Adobe patched only the latter in April, leaving the other two unchanged for more than 90 days, until two security researchers published a. write up On July 29, it was explained in detail how the vulnerabilities work and how they can be exploited.

    Adobe finally released a security update on August 9 to address the CVE-2025-54253 vulnerability, confirming that proof-of-concept exploit code was already publicly available.

    As Searchlight Cyber ​​explained, CVE-2025-54253 is an authentication bypass that leads to remote code execution (RCE) via Struts devmod. The researchers also advised administrators to restrict Internet access to AEM forms when deployed as a standalone application if they cannot patch the software immediately.

    CISA now has This vulnerability was added for this List of known exploited vulnerabilitiesAccording to Order Binding Operational Directive (BOD) 22-01 issued in November 2021, Federal Civil Executive Branch (FCEB) agencies have been given three weeks to secure their systems until November 5.

    Although BOD 22-01 targets US federal agencies, the cybersecurity agency encouraged all organizations, including the private sector, to prioritize patching their systems against this actively exploited flaw as quickly as possible.

    “Apply mitigations according to vendor instructions, follow BOD 22-01 guidance applicable to cloud services, or discontinue use of the product if mitigations are not available.” CISA warned On Wednesday.

    “These types of vulnerabilities are a persistent attack vehicle for malicious cyber actors and pose significant risks to the federal enterprise,” it was added,


    PICS BAS Summit

    attend Breach and Attack Simulation Summit and experience future of security verificationHear from top experts and see how AI-powered BAS Changing breach and attack simulations.

    Don’t miss the event that will shape the future of your security strategy

    ADOBE attacks Flaw Maximumsevere
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleFinally, hook-free earbuds that actually stay in my ears (no matter what I’m doing)
    Next Article I removed my AirPods within minutes of listening to these Bose earbuds – this is what reassures me
    PineapplesUpdate
    • Website

    Related Posts

    Startups

    A new earbud security flaw could leave you a victim of remote spying – here’s how to fix it

    January 18, 2026
    AI/ML

    Adobe Firefly brings support for Image 5 layers, which will let creators create custom models

    October 28, 2025
    AI/ML

    Adobe launches AI assistant for Express and Photoshop

    October 28, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    Google tests AI-operated audio overview in search results for some questions

    June 16, 20250 Views
    Our Picks

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2026 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.