RaqibCTI
CVE

CVE-2025-53690

P2
Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability
Sitecore · Multiple Products
Date added (CISA)
2025-09-04
Remediation due
2025-09-25
Known ransomware use
Not indicated
Remediation priority
P2past CISA due date

Description

Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud contain a deserialization of untrusted data vulnerability involving the use of default machine keys. This flaw allows attackers to exploit exposed ASP.NET machine keys to achieve remote code execution.

Source: NVD ↗ · CISA KEV Catalog ↗

CVE-2025-53690: Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability · RaqibCTI