Adobe AEM Forms JEE APSB26-151: Critical authz/SSRF/input flaws (CVE-2026-75745/81995/82000) — hotfix / LTS SP3
Adobe Experience Manager Forms JEE APSB26-151 (CVE records 22 September 2026; SecurityWeek 23 Sep) patches six vulnerabilities including three Critical: CVE-2026-75745 (incorrect authorization), CVE-2026-81995 (improper input validation → RCE, Adobe CVSS 9.1), CVE-2026-82000 (SSRF → privilege escalation, Adobe CVSS 9.6), plus High SSRF/XSS/CSRF. Affected: AEM 6.5 Forms JEE 6.5.25 and AEM 6.5 LTS Forms JEE SP2. Fixes: 6.5.25 with AEMForms-6.5.0-0134 Hotfix; 6.5 LTS SP3. Priority 2. Adobe not aware of in-the-wild exploitation. Companion to Connect APSB26-150 same day. Primary: Adobe APSB26-151 helpx; metadata: CVE.report; wire: SecurityWeek 23 Sep 2026.
- Product
- Adobe Experience Manager (AEM) Forms JEE (6.5 and 6.5 LTS)
- Versions
- Affected: AEM 6.5 Forms JEE 6.5.25; AEM 6.5 LTS Forms JEE SP2. Fix: 6.5.25 + AEMForms-6.5.0-0134 Hotfix; LTS SP3.
- CVSS
- (CVE-2026-82000 CVSS 3.1 Critical, Adobe); also 9.1 (CVE-2026-81995)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N - Exploited in Australia?
- unknown
- Patch to
- Apply AEMForms-6.5.0-0134 Hotfix on 6.5.25 or upgrade 6.5 LTS Forms JEE to SP3 (APSB26-151 Priority 2)
Primary: Adobe APSB26-151 — AEM Forms JEE security update (22 Sep 2026) · Vendor: Adobe — APSB26-151 · CVE: CVE-2026-75745, CVE-2026-81995, CVE-2026-82000 · CVE.report — CVE-2026-82000 / 81995 / 75745; also SecurityWeek 23 Sep 2026
