Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (XM): through 9.0; Experience Platform (XP): through 9.0.
The vulnerability (CWE-502) results from improper deserialization of user-supplied input data. An attacker can submit a specially crafted payload that is executed as server-side code during the deserialization process. A network attack vector without authentication requirements (PR:N, UI:N) means the exploit can be performed remotely without any victim interaction. The Google Cloud Threat Intelligence reference indicates a connection to the ViewState deserialization mechanism as the attack vector.
A successful attack leads to complete system takeover — the attacker can execute arbitrary code on the server, access sensitive data, modify application content, and potentially perform lateral movement within the internal network (scope impact S:C, full confidentiality, integrity and availability: C:H/I:H/A:H).
Apply patches available from the vendor immediately in accordance with article KB1003865 in the Sitecore support database (https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1003865). Until the fix is deployed, it is recommended to restrict access to Sitecore instances at the firewall level and monitor traffic for unexpected deserialization requests.
Sitecore Experience Manager (XM) in versions up to and including 9.0 and Sitecore Experience Platform (XP) in versions up to and including 9.0. Also affects Sitecore Managed Cloud environments and Sitecore Experience Commerce deployments using these components.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HSitecore Experience Commerce
APPSitecore≤ 9.0Sitecore Experience Manager
APPSitecore≤ 9.0Sitecore Experience Platform
APPSitecore≤ 9.0Sitecore Managed Cloud
APPSitecoreall versions
CISA KEV — detailsi
- Vendori
- Sitecore
- Producti
- Multiple Products
- Added to KEVi
- September 4, 2025
- Remediation deadline (US Federal)i
- September 25, 2025(overdue)
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud contain a deserialization of untrusted data vulnerability involving the use of default machine keys. This flaw allows attackers to exploit exposed ASP.NET machine keys to achieve remote code execution.
Related vulnerabilities
RCE poprzez insecure deserialization w Sitecore Experience Platform
RCE przez deserializację w module anti-CSRF Sitecore CMS/XP
Unsafe Reflection umożliwiający Cache Poisoning w Sitecore XM/XP
RCE w produktach Sitecore Experience — krytyczna podatność na zdalne wykonanie kodu
RCE przez deserializację w Sitecore Experience Platform (ValidationResult.aspx)