Adobe disclosed a critical (CVSS 9.1) improper input validation vulnerability in AEM Forms JEE that lets a high-privileged attacker execute arbitrary code remotely without user interaction.
What Is It
CVE-2026-81995 is an Improper Input Validation weakness (CWE-20) in Adobe Experience Manager Forms JEE. Per Adobe's advisory, the flaw "could result in arbitrary code execution in the context of the current user." An attacker holding high privileges can exploit it over the network to run arbitrary code, and exploitation does not require user interaction.
The CVSS v3.1 vector is AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, base score 9.1, rated CRITICAL. Scope is marked as changed, meaning successful exploitation impacts resources beyond the vulnerable component's security authority. The CVE was published 2026-09-22 by Adobe PSIRT and remains in "Awaiting Analysis" status at NVD.
Why It Matters
The combination of network attack vector, low attack complexity, no user interaction, changed scope, and high impact across confidentiality, integrity, and availability is what pushes this to 9.1 despite requiring high privileges. AEM Forms JEE typically sits in document- and workflow-processing roles inside enterprise environments, so a scope-changing code execution primitive is meaningful even with an authenticated starting point.
CVE-2026-81995 does not appear in CISA's Known Exploited Vulnerabilities catalog as of 2026-09-22; active exploitation is not confirmed, and no federal remediation deadline applies. Prioritization should be driven by the CVSS rating and exposure of affected instances.
What's Vulnerable
Two product lines are affected:
- AEM 6.5 Forms JEE: all versions up to and including 6.5.25
- AEM 6.5 LTS Forms JEE: all versions up to and including 6.5 LTS SP2
Adobe lists the default status for other versions as unaffected.
Patch Status
Fixed builds are available:
- AEM 6.5 Forms JEE: 6.5.25 with the AEMForms-6.5.0-0134 Hotfix
- AEM 6.5 LTS Forms JEE: 6.5 LTS SP3
Administrators should apply the hotfix or service pack per Adobe Security Bulletin APSB26-151. Adobe's bulletin lists no workarounds or mitigations for this issue; patching is the only remediation Adobe provides.
Sources
- Adobe Security Bulletin APSB26-151 (AEM Forms), https://helpx.adobe.com/security/products/aem-forms/apsb26-151.html
- NVD, CVE-2026-81995, https://nvd.nist.gov/vuln/detail/CVE-2026-81995
- CISA Known Exploited Vulnerabilities Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog