CVE-2025-27218
largeInsecure Deserialization RCE in Sitecore Experience Manager (XM) and XP 10.4
Sitecore Experience Manager (XM) and Experience Platform (XP) version 10.4, prior to the KB1002844 hotfix, are vulnerable to remote code execution through insecure deserialization, classified under CWE-94 (improper control of code generation). The flaw is reachable over the network with no privileges or user interaction required per the CVSS vector (AV:N/AC:L/PR:N/UI:N), and successful exploitation gives an attacker code execution on the affected instance; the published base score is 5.3 (medium). Any organization running XM/XP 10.4 without the KB1002844 fix is affected, and related coverage highlights elevated RCE risk in enterprise deployments as well as a related hard-coded 'b' password issue in Sitecore XP. No exploitation has been documented so far: the flaw is not in CISA KEV and no public proof-of-concept is known. However, EPSS assigns a 65% probability of exploitation within the next 30 days (99th percentile), so defenders should treat near-term exploitation attempts as likely.
What to do: Apply the Sitecore hotfix KB1002844 to all XM/XP 10.4 instances, or upgrade to a release that includes it, and inventory internet-facing Sitecore servers to confirm none remain unpatched. Until patched, restrict network exposure of Sitecore servers and monitor for exploitation attempts given the 65% EPSS. Also review related coverage of the hard-coded 'b' password issue in Sitecore XP and apply any associated vendor guidance.
| Sitecore Experience Manager (XM) | 10.4 before hotfix KB1002844 |
| Sitecore Experience Platform (XP) | 10.4 before hotfix KB1002844 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Sitecore Experience Manager (XM) and Experience Platform (XP) 10.4 before KB1002844 allow remote code execution through insecure deserialization.
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N