CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2025-53690

CVSS 9.0v3.1pub. 2025-09-03upd. 2025-10-30

Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (XM): through 9.0; Experience Platform (XP): through 9.0.

🤖 AI Analysis
How it works

The vulnerability (CWE-502) results from improper deserialization of user-supplied input data. An attacker can submit a specially crafted payload that is executed as server-side code during the deserialization process. A network attack vector without authentication requirements (PR:N, UI:N) means the exploit can be performed remotely without any victim interaction. The Google Cloud Threat Intelligence reference indicates a connection to the ViewState deserialization mechanism as the attack vector.

Impact

A successful attack leads to complete system takeover — the attacker can execute arbitrary code on the server, access sensitive data, modify application content, and potentially perform lateral movement within the internal network (scope impact S:C, full confidentiality, integrity and availability: C:H/I:H/A:H).

Mitigation & patch

Apply patches available from the vendor immediately in accordance with article KB1003865 in the Sitecore support database (https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1003865). Until the fix is deployed, it is recommended to restrict access to Sitecore instances at the firewall level and monitor traffic for unexpected deserialization requests.

Who is affected

Sitecore Experience Manager (XM) in versions up to and including 9.0 and Sitecore Experience Platform (XP) in versions up to and including 9.0. Also affects Sitecore Managed Cloud environments and Sitecore Experience Commerce deployments using these components.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Sitecore Experience Commerce

    APP
    Sitecore
    ≤ 9.0
  • Sitecore Experience Manager

    APP
    Sitecore
    ≤ 9.0
  • Sitecore Experience Platform

    APP
    Sitecore
    ≤ 9.0
  • Sitecore Managed Cloud

    APP
    Sitecore
    all versions

CISA KEV — detailsi

Vendori
Sitecore
Producti
Multiple Products
Added to KEVi
September 4, 2025
Remediation deadline (US Federal)i
September 25, 2025(overdue)
Required action (CISA)i

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud contain a deserialization of untrusted data vulnerability involving the use of default machine keys. This flaw allows attackers to exploit exposed ASP.NET machine keys to achieve remote code execution.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 25 września 2025
Tags
Deserialization
CWE
References

Related vulnerabilities

CVE-2021-42237CRITICAL9.8⚠ KEVPL ✓same product

RCE poprzez insecure deserialization w Sitecore Experience Platform

CVE-2019-9874CRITICAL9.8⚠ KEVPL ✓same product

RCE przez deserializację w module anti-CSRF Sitecore CMS/XP

CVE-2025-53693CRITICAL9.8PL ✓same product

Unsafe Reflection umożliwiający Cache Poisoning w Sitecore XM/XP

CVE-2023-35813CRITICAL9.8PL ✓same product

RCE w produktach Sitecore Experience — krytyczna podatność na zdalne wykonanie kodu

CVE-2023-27068CRITICAL9.8PL ✓same product

RCE przez deserializację w Sitecore Experience Platform (ValidationResult.aspx)