Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-75745: Adobe AEM Forms JEE can run attacker code
CVE-2026-75745 · published 1 day ago
Summary
The Adobe Experience Manager Forms JEE component in version 6.5 (including the LTS release) can be tricked into executing code that an attacker provides, without needing any user to click anything. This means a malicious actor could take actions on the system with the same permissions as the compromised user. Apply the latest security updates from Adobe as soon as possible to close the gap.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| adobe | aem 6.5 forms jee | <= 6.5.25 |
| adobe | aem 6.5 lts forms jee | <= 6.5 LTS SP2 |
Original advisory text
Adobe Experience Manager Forms JEE | Incorrect Authorization (CWE-863)
Adobe Experience Manager Forms JEE is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Severity
10.0
Critical
CVSS 3.1: 10.0 (MITRE)
Type
CWE-863Incorrect Authorization
Timeline
Published22 Sep 2026
Updated22 Sep 2026
First seen22 Sep 2026
Track software like this
Free during beta