Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution.
Source: NVD ↗ · CISA KEV Catalog ↗