CVE-2025-64538
Adobe Experience Manager vulnerability analysis and mitigation

Overview

CVE-2025-64538 is a DOM-based Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager (AEM) that allows unauthenticated remote attackers to inject and execute malicious scripts in the context of a victim's browser. It affects AEM versions 6.5.23 and earlier (on-premises) and AEM Cloud Service versions prior to 2025.12.0. The vulnerability was published on December 10, 2025, with Adobe releasing the advisory (APSB25-115) on December 9, 2025. It carries a CVSS v3.1 base score of 9.3 (Critical) (Adobe Advisory, Feedly).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically the DOM-based variant, meaning the malicious payload is processed and executed entirely within the browser's DOM without necessarily being reflected from the server. An attacker crafts a malicious web page or link that, when visited by an authenticated AEM user, causes the browser to execute injected JavaScript in the AEM application's security context. No privileges are required on the attacker's side, but user interaction is required — the victim must visit or be socially engineered into visiting the crafted page. No public proof-of-concept exploit code has been identified at this time (Adobe Advisory, Feedly).

Impact

Successful exploitation enables session hijacking, allowing an attacker to steal authenticated session tokens and impersonate the victim within AEM. The changed scope (S:C) in the CVSS vector indicates the impact can extend beyond the vulnerable component itself, potentially affecting other systems or data accessible to the compromised session. Confidentiality and integrity are both rated High — sensitive content, configurations, or user data managed within AEM could be exfiltrated or tampered with — while availability is not directly impacted (Adobe Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify publicly accessible Adobe Experience Manager instances running version 6.5.23 or earlier, or AEM Cloud Service prior to 2025.12.0, using search engines, Shodan, or Censys.
  2. Identify vulnerable DOM sink: Analyze the AEM application's client-side JavaScript to locate DOM-based XSS sinks (e.g., document.write, innerHTML, location.hash processing) that accept attacker-controlled input without proper sanitization.
  3. Craft malicious payload: Construct a URL or web page that passes a malicious JavaScript payload through the vulnerable DOM sink — for example, via a URL fragment (#) or query parameter that is read and written into the DOM unsanitized.
  4. Deliver to victim: Use phishing, malicious links, or a compromised third-party site to lure an authenticated AEM user into visiting the crafted URL or page.
  5. Execute payload and hijack session: The victim's browser executes the injected script in the AEM origin context, enabling the attacker to steal session cookies, perform actions on behalf of the victim, or exfiltrate sensitive data from the AEM instance (Adobe Advisory, Feedly).

Indicators of compromise

  • Network: Unusual outbound HTTP requests from AEM users' browsers to attacker-controlled domains (e.g., data exfiltration via fetch or XMLHttpRequest to external IPs); unexpected cross-origin requests originating from AEM pages.
  • Logs: AEM access logs showing requests to AEM pages with suspicious URL fragments or query parameters containing encoded JavaScript (e.g., <script>, javascript:, onerror=, %3Cscript%3E); browser console errors related to Content Security Policy violations if CSP is enabled.
  • Session/Auth: Unexpected session activity from unusual IP addresses or geolocations following a user visiting an external link; multiple authenticated actions performed in rapid succession inconsistent with normal user behavior.
  • File System: New or modified AEM content pages or components containing embedded <script> tags or JavaScript event handlers not present in authorized templates.

Mitigation and workarounds

Adobe has released patches addressing this vulnerability: upgrade AEM on-premises to version 6.5.24.0 or later, and AEM Cloud Service to 2025.12.0 or later (Adobe Advisory). As interim mitigations, organizations should implement a strict Content Security Policy (CSP) to restrict unauthorized script execution, enforce input validation and output encoding on all user-supplied data rendered in the DOM, and educate users about phishing and social engineering risks. Monitoring for anomalous session activity and suspicious URL patterns in AEM access logs is also recommended.

Community reactions

The Belgium Centre for Cybersecurity (CCB) issued a warning advising organizations to patch immediately, characterizing the vulnerability as critical XSS in AEM (CCB Advisory). CISA referenced the vulnerability in its weekly bulletin (SB25-349). Coverage has been largely limited to automated vulnerability tracking platforms and national CERTs, with no significant independent researcher commentary or social media discussion identified at this time.

Additional resources


SourceThis report was generated using AI

Related Adobe Experience Manager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-48359CRITICAL9.6
  • Adobe Experience Manager logoAdobe Experience Manager
  • cpe:2.3:a:adobe:experience_manager
NoYesJul 14, 2026
CVE-2026-48310HIGH8.6
  • Adobe Experience Manager logoAdobe Experience Manager
  • cpe:2.3:a:adobe:experience_manager
NoYesJul 14, 2026
CVE-2026-48355MEDIUM5.4
  • Adobe Experience Manager logoAdobe Experience Manager
  • cpe:2.3:a:adobe:experience_manager
NoYesJul 14, 2026
CVE-2026-48263MEDIUM5.4
  • Adobe Experience Manager logoAdobe Experience Manager
  • cpe:2.3:a:adobe:experience_manager
NoYesJul 14, 2026
CVE-2026-48262MEDIUM5.4
  • Adobe Experience Manager logoAdobe Experience Manager
  • cpe:2.3:a:adobe:experience_manager
NoYesJul 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management