Cyber & AI intelligence
Wasteland.
Briefs indexed2842
Issues29
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-81995 2026-09-22

CVE-2026-81995: Critical Code Execution Flaw in Adobe Experience Manager Forms JEE

"Adobe disclosed a critical (CVSS 9.1) improper input validation vulnerability in AEM Forms JEE that lets a high-privileged attacker execute arbitrary code remotely without user interaction."

Adobe disclosed a critical (CVSS 9.1) improper input validation vulnerability in AEM Forms JEE that lets a high-privileged attacker execute arbitrary code remotely without user interaction.

What Is It

CVE-2026-81995 is an Improper Input Validation weakness (CWE-20) in Adobe Experience Manager Forms JEE. Per Adobe's advisory, the flaw "could result in arbitrary code execution in the context of the current user." An attacker holding high privileges can exploit it over the network to run arbitrary code, and exploitation does not require user interaction.

The CVSS v3.1 vector is AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, base score 9.1, rated CRITICAL. Scope is marked as changed, meaning successful exploitation impacts resources beyond the vulnerable component's security authority. The CVE was published 2026-09-22 by Adobe PSIRT and remains in "Awaiting Analysis" status at NVD.

Why It Matters

The combination of network attack vector, low attack complexity, no user interaction, changed scope, and high impact across confidentiality, integrity, and availability is what pushes this to 9.1 despite requiring high privileges. AEM Forms JEE typically sits in document- and workflow-processing roles inside enterprise environments, so a scope-changing code execution primitive is meaningful even with an authenticated starting point.

CVE-2026-81995 does not appear in CISA's Known Exploited Vulnerabilities catalog as of 2026-09-22; active exploitation is not confirmed, and no federal remediation deadline applies. Prioritization should be driven by the CVSS rating and exposure of affected instances.

What's Vulnerable

Two product lines are affected:

Adobe lists the default status for other versions as unaffected.

Patch Status

Fixed builds are available:

Administrators should apply the hotfix or service pack per Adobe Security Bulletin APSB26-151. Adobe's bulletin lists no workarounds or mitigations for this issue; patching is the only remediation Adobe provides.

Sources