CVE-2019-9874
KEV PoC largeUnauthenticated .NET Deserialization RCE in Sitecore CMS and Experience Platform
CISA: Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability
CVE-2019-9874 is a deserialization flaw (CWE-502) in the Sitecore.Security.AntiCSRF module that lets an unauthenticated attacker run arbitrary code remotely. It is triggered by sending a crafted serialized .NET object in the HTTP POST parameter __CSRFTOKEN, which the module deserializes without validation. Successful exploitation yields full remote code execution with the privileges of the web application, with confidentiality, integrity, and availability all impacted. Users of Sitecore CMS 7.0 through 7.2 and Sitecore Experience Platform (XP) 7.5 through 8.2 are affected. The flaw carries a critical CVSS 3.1 score of 9.8, a very high EPSS score of 83.7%, and was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-26, indicating active exploitation in the wild; ransomware use is currently unknown.
What to do: Upgrade affected Sitecore CMS (7.0–7.2) and XP (7.5–8.2) deployments to a patched, currently supported release per Sitecore's security guidance, as required by CISA's KEV/BOD 22-01 action for federal agencies. Until patched, restrict network access to vulnerable Sitecore instances and monitor IIS/web logs for unauthenticated POST requests containing oversized or anomalous __CSRFTOKEN values. A public technical advisory with exploitation details is available from Synacktiv, so treat exploitability as confirmed.
| Sitecore CMS | 7.0 to 7.2 |
| Sitecore Experience Platform (XP) | 7.5 to 8.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allows an unauthenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN.
- Affected
- Sitecore CMS and Experience Platform (XP)
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- sitecore
- Products
- cms, experience platform
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H