Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required to exploit this vulnerability.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSitecore Experience Platform
APPSitecore7.58.08.18.2
CISA KEV — detailsi
- Vendori
- Sitecore
- Producti
- XP
- Added to KEVi
- March 25, 2022
- Remediation deadline (US Federal)i
- April 15, 2022(overdue)
- Ransomwarei
- Active ransomware campaigns exploit this vulnerability
Required action (CISA)i
Apply updates per vendor instructions.
CISA descriptioni
Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution.
🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
☠️WYKORZYSTYWANE W RANSOMWARE⏰CISA DEADLINE: 15 kwietnia 2022
Tags
Deserialization
References
Related vulnerabilities
CVE-2025-53690CRITICAL9.0⚠ KEVPL ✓same product
Krótki tytuł podatności po polsku (max 80 znaków)
CVE-2019-9874CRITICAL9.8⚠ KEVPL ✓same product
RCE przez deserializację w module anti-CSRF Sitecore CMS/XP
CVE-2025-53693CRITICAL9.8PL ✓same product
Unsafe Reflection umożliwiający Cache Poisoning w Sitecore XM/XP
CVE-2023-35813CRITICAL9.8PL ✓same product
RCE w produktach Sitecore Experience — krytyczna podatność na zdalne wykonanie kodu
CVE-2023-27068CRITICAL9.8PL ✓same product
RCE przez deserializację w Sitecore Experience Platform (ValidationResult.aspx)