
🚨 ADOBE AEM FORMS JEE CRITICAL — UNAUTHENTICATED AUTHORIZATION BYPASS CAN ENABLE RCE Adobe has released APSB26-151 for Experience Manager Forms on JEE, fixing multiple Critical flaws. The lead issue is CVE-2026-75745: Incorrect Authorization allowing unauthenticated remote arbitrary code execution (CVSS 9.8). • Bulletin: APSB26-151 (Priority 2) — published September 22, 2026 • Lead CVE: CVE-2026-75745 — Incorrect Authorization → arbitrary code execution — Critical CVSS 9.8 (AV:N/AC:L/PR:N/UI:N/S:C) • Also Critical: CVE-2026-81995 (Improper Input Validation / RCE, CVSS 9.1), CVE-2026-82000 / CVE-2026-81999 (SSRF privilege escalation), CVE-2026-75744 (Stored XSS / RCE), plus Critical CSRF security-feature bypass (CVSS 7.1) • Affects: AEM 6.5 LTS Forms SP2 and earlier; AEM 6.5 Forms 6.5.25 and earlier • Fix: AEM 6.5 LTS Forms Service Pack 3; AEM 6.5 Forms 6.5.25 hotfix AEMForms-6.5.0-0134 • Exploitation in the wild: Adobe reports none known as of the bulletin; not on CISA KEV ⚠️ Analyst Note: This is the official Adobe PSIRT bulletin APSB26-151. The unauthenticated network-facing authorization flaw (CVE-2026-75745) is the clearest urgent item for internet-exposed AEM Forms JEE deployments. Adobe rates the update Priority 2 and is not aware of active exploitation; still treat Critical unauth RCE-class issues as patch-now for exposed Forms servers. Official: https://helpx.adobe.com/security/products/aem-forms/apsb26-151.html #DDW #DarkWeb #CyberSecurity #ThreatIntelligence #Adobe #AEM #CVE
