ZeroHour

CVE-2025-27218

large

Insecure Deserialization RCE in Sitecore Experience Manager (XM) and XP 10.4

CVSS 3.1
5.3 medium
EPSS
65%p99
Published
()
Modified
AI analysis

Sitecore Experience Manager (XM) and Experience Platform (XP) version 10.4, prior to the KB1002844 hotfix, are vulnerable to remote code execution through insecure deserialization, classified under CWE-94 (improper control of code generation). The flaw is reachable over the network with no privileges or user interaction required per the CVSS vector (AV:N/AC:L/PR:N/UI:N), and successful exploitation gives an attacker code execution on the affected instance; the published base score is 5.3 (medium). Any organization running XM/XP 10.4 without the KB1002844 fix is affected, and related coverage highlights elevated RCE risk in enterprise deployments as well as a related hard-coded 'b' password issue in Sitecore XP. No exploitation has been documented so far: the flaw is not in CISA KEV and no public proof-of-concept is known. However, EPSS assigns a 65% probability of exploitation within the next 30 days (99th percentile), so defenders should treat near-term exploitation attempts as likely.

What to do: Apply the Sitecore hotfix KB1002844 to all XM/XP 10.4 instances, or upgrade to a release that includes it, and inventory internet-facing Sitecore servers to confirm none remain unpatched. Until patched, restrict network exposure of Sitecore servers and monitor for exploitation attempts given the 65% EPSS. Also review related coverage of the hard-coded 'b' password issue in Sitecore XP and apply any associated vendor guidance.

Affected
Sitecore Experience Manager (XM)10.4 before hotfix KB1002844
Sitecore Experience Platform (XP)10.4 before hotfix KB1002844
Estimated exposure
largeon the order of tens of thousands of internet-exposed Sitecore systems (10.4 pre-hotfix subset) — Sitecore is an enterprise CMS/DXP with thousands of large-organization customers running multi-server, internet-facing deployments, so assuming the 10.4 line represents a substantial share of active installs plausibly yields tens of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Sitecore Experience Manager (XM) and Experience Platform (XP) 10.4 before KB1002844 allow remote code execution through insecure deserialization.

Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news