Loading HuntDB...

Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability

Added Sept. 4, 2025 Due Sept. 25, 2025 CVE-2025-53690
On Track Sitecore / Multiple Products CWE-502

Description

Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud contain a deserialization of untrusted data vulnerability involving the use of default machine keys. This flaw allows attackers to exploit exposed ASP.NET machine keys to achieve remote code execution.

Required Action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

References

Additional Information

Catalog Version
2025.09.04
Catalog Released
Sept. 4, 2025
Days Until Due
16 days
Last Updated
12 hours ago