BlackTree Security · Infrastructure · Automation · AI

One Request Could Make Adobe AEM Forms Run Code Without a Login

According to Adobe bulletin APSB26-151, Adobe has patched six vulnerabilities in Experience Manager Forms on Java Enterprise Edition. The most urgent can execute code over the network without authentication or user interaction.

CVE-2026-75745 is an incorrect-authorization flaw rated 9.8. Adobe’s vector records network access, low complexity, no privileges and no user interaction. The vendor says it is not aware of exploitation in the wild.

The bulletin contains six different attack paths

VulnerabilityImpactPrerequisiteScore
CVE-2026-75745Arbitrary code executionNo authentication or user interaction9.8
CVE-2026-81995Arbitrary code executionHigh privileges9.1
CVE-2026-82000Privilege escalation through SSRFLow privileges9.1
CVE-2026-81999Privilege escalation through SSRFHigh privileges8.7
CVE-2026-75744Code execution through stored XSSHigh privileges and user interaction8.1
CVE-2026-75743Security-feature bypass through CSRFNo privileges, user interaction required7.1
Impact, prerequisites and scores from Adobe bulletin APSB26-151.

Adobe labels every row Critical in the primary bulletin, although several scores and prerequisites differ materially. Treating the six as one generic “critical update” would hide the unauthenticated path and make investigation priorities less precise.

The fixed build depends on the AEM Forms line

Adobe lists AEM 6.5 LTS Forms Service Pack 2 and earlier for an update to Service Pack 3. AEM 6.5 Forms 6.5.25 and earlier requires the AEMForms-6.5.0-0134 hotfix on 6.5.25. Adobe directs customers on versions 6.4, 6.3 and 6.2 to Customer Care.

  • Inventory AEM Forms on JEE separately from other Experience Manager components.
  • Record the exact product line, service pack, hotfix and operating system for every node.
  • Prioritise Internet-reachable instances and the unauthenticated path in CVE-2026-75745.
  • Apply Service Pack 3 or hotfix AEMForms-6.5.0-0134 as appropriate and verify the running build.
  • Review authentication, application and outbound-request logs from the vulnerable period where exposure was significant.
  • Do not use the absence of known exploitation as proof that a particular instance was not tested or attacked.

Adobe assigns the update priority 2, which ordinarily supports deployment within 30 days. Organisations with externally reachable AEM Forms should set their own urgency from the no-login attack vector, data sensitivity and ability to inspect the exposed period rather than treating the vendor priority as a universal waiting period.

No public proof of concept or confirmed exploitation was established in the reviewed sources. The case for prompt action comes from the trust boundary and the available fix: one request path can reach arbitrary code before the attacker has an account.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *