# Adobe patches critical AEM Forms JEE flaws

Published: 2026-09-23 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/ca8ba873-7326-5c8e-b473-6a661bb5af69/adobe-patches-critical-aem-forms-jee-flaws

> Adobe fixed six critical vulnerabilities in AEM Forms JEE, including an unauthenticated RCE flaw rated CVSS 10.0, with no known active exploitation.

The Dutch National Cyber Security Centre (NCSC-NL) issued an advisory summarizing six vulnerabilities patched by Adobe in Experience Manager (AEM) Forms on Java Enterprise Edition, affecting AEM 6.5 Forms and AEM 6.5 LTS Forms. All six flaws are rated critical and span multiple vulnerability classes: improper authorization, insufficient input validation, Server-Side Request Forgery (SSRF), Cross-Site Scripting (XSS), and Cross-Site Request Forgery (CSRF).

Two of the six vulnerabilities can be exploited remotely without authentication. The most severe, CVE-2026-75745, carries a CVSS score of 10.0 (NCSC lists 9.8 in the body text, 10.0 in the reference table) and allows unauthenticated, no-interaction remote code execution. Successful exploitation across the set of flaws could result in arbitrary code execution, privilege escalation, and bypass of security controls. Adobe states it is not aware of any active exploitation in the wild.

Defenders running AEM 6.5 Forms or AEM 6.5 LTS Forms on JEE should prioritize applying Adobe's security updates, particularly given the unauthenticated RCE vector. As this is a Java EE deployment often exposed for form processing and document generation, organizations should verify patch status across all instances and review external exposure of AEM Forms endpoints as an interim mitigation while patching is completed.

## Mentioned in this report

- Vulnerabilities: CVE-2026-75743, CVE-2026-75744, CVE-2026-75745, CVE-2026-81995, CVE-2026-81999, CVE-2026-82000

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0390.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/ca8ba873-7326-5c8e-b473-6a661bb5af69/adobe-patches-critical-aem-forms-jee-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
