ZeroHour

CVE-2019-9874

KEV PoC large

Unauthenticated .NET Deserialization RCE in Sitecore CMS and Experience Platform

CISA: Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability

CVSS 3.1
9.8 critical
EPSS
84%p100
Published
()
KEV added
AI analysis

CVE-2019-9874 is a deserialization flaw (CWE-502) in the Sitecore.Security.AntiCSRF module that lets an unauthenticated attacker run arbitrary code remotely. It is triggered by sending a crafted serialized .NET object in the HTTP POST parameter __CSRFTOKEN, which the module deserializes without validation. Successful exploitation yields full remote code execution with the privileges of the web application, with confidentiality, integrity, and availability all impacted. Users of Sitecore CMS 7.0 through 7.2 and Sitecore Experience Platform (XP) 7.5 through 8.2 are affected. The flaw carries a critical CVSS 3.1 score of 9.8, a very high EPSS score of 83.7%, and was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-26, indicating active exploitation in the wild; ransomware use is currently unknown.

What to do: Upgrade affected Sitecore CMS (7.0–7.2) and XP (7.5–8.2) deployments to a patched, currently supported release per Sitecore's security guidance, as required by CISA's KEV/BOD 22-01 action for federal agencies. Until patched, restrict network access to vulnerable Sitecore instances and monitor IIS/web logs for unauthenticated POST requests containing oversized or anomalous __CSRFTOKEN values. A public technical advisory with exploitation details is available from Synacktiv, so treat exploitability as confirmed.

Affected
Sitecore CMS7.0 to 7.2
Sitecore Experience Platform (XP)7.5 to 8.2
Estimated exposure
largeon the order of tens of thousands of internet-exposed Sitecore CMS/XP deployments (estimated) — Sitecore XP is an enterprise CMS deployed by thousands of organizations with internet-facing content delivery servers, and public internet scans have catalogued tens of thousands of Sitecore instances, a meaningful share still running…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allows an unauthenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN.

CISA Known Exploited Vulnerability
Affected
Sitecore CMS and Experience Platform (XP)
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
sitecore
Products
cms, experience platform
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news