CVE-2025-53690

9.5 CISA KEV

Sitecore · Experience Manager (XM), Experience Platform (XP)

Sitecore Experience Manager and Experience Platform are vulnerable to a deserialization of untrusted data flaw that allows for arbitrary code injection.

Executive summary

This critical deserialization vulnerability in Sitecore Experience Manager and Experience Platform is currently being actively exploited in the wild, posing a severe risk of unauthorized code execution.

Vulnerability

The vulnerability arises from improper deserialization of untrusted data (CWE-502), which allows an unauthenticated remote attacker to inject and execute arbitrary code on the affected server.

Business impact

The potential for remote code execution represents the highest level of security risk, as it allows attackers to gain full control over the affected Sitecore environment. This can lead to the total compromise of sensitive customer data, deep integration into the corporate network, and significant operational downtime. Given the CVSS score of 9.5 and the confirmed active exploitation of this vulnerability in the wild, the business risk is extreme.

Remediation

Immediate Action: Review the official Sitecore security advisory (KB1003865) and apply the recommended patches or configuration changes immediately to prevent exploitation.

Proactive Monitoring: Monitor server logs for unexpected process execution, unusual outbound network connections from the web server, or unauthorized file modifications in the web root.

Compensating Controls: Deploy or update Web Application Firewall (WAF) rules to inspect and block malicious serialized objects in incoming HTTP requests, which may provide temporary protection while the primary patch is being staged.

Exploitation status

Public Exploit Available: Yes, multiple public proofs-of-concept exist on GitHub.

Analyst recommendation

Due to the critical severity of this vulnerability and the confirmed evidence of active exploitation, immediate remediation is mandatory. Organizations running Sitecore XM or XP versions 9.0 or earlier must prioritize the application of vendor-supplied patches. If patching is not immediately feasible, ensure that compensating controls and enhanced monitoring are in place to detect and block potential exploitation attempts.

History

  1. Disclosed CVE record published
  2. Published in the daily brief critical section, carried in 21 daily briefs, Sep 3 to Sep 24
  3. Analyst report written

Sources

Originally found and disclosed by Mandiant Threat Defense, per the CVE Program record.