CVE-2025-53690
KEV PoC largeUnauthenticated ViewState Deserialization RCE in Sitecore XM/XP
CISA: Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability
CVE-2025-53690 is a critical (CVSS 9.0) deserialization-of-untrusted-data flaw (CWE-502) in Sitecore Experience Manager (XM) and Experience Platform (XP) through version 9.0 that enables unauthenticated code injection. Public threat reporting (Google Cloud/Mandiant) and news coverage tie the flaw to ASP.NET ViewState deserialization performed using exposed (default or leaked) ASP.NET machine keys, so a remote attacker who can reach a Sitecore site can submit a crafted, signed ViewState payload that is deserialized server-side, resulting in remote code execution. A successful unauthenticated attacker gains arbitrary code execution on the web server with the scope-changed (S:C) impact of high confidentiality, integrity and availability loss. Organizations running internet-facing Sitecore XM/XP deployments — including Experience Commerce and Managed Cloud deployments — are in scope. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-09-04, and reporting links the activity to a China-linked APT (UAT-8837) targeting North American critical infrastructure.
What to do: Apply Sitecore's security updates to all affected XM/XP deployments (through 9.0) and follow the vendor's mitigations as required by CISA KEV/BOD 22-01, or discontinue use if patching is not possible. Per the public reporting, rotate any exposed or default ASP.NET machineKey values (e.g., in web.config) on internet-facing Sitecore servers, since exposed machine keys enable the ViewState deserialization attacks. Inventory internet-exposed Sitecore instances and review them for signs of compromise.
| Sitecore Experience Manager (XM) | through 9.0 |
| Sitecore Experience Platform (XP) | through 9.0 |
| Sitecore Experience Commerce | — |
| Sitecore Managed Cloud | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (XM): through 9.0; Experience Platform (XP): through 9.0.
- Affected
- Sitecore Multiple Products
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- sitecore
- Products
- experience commerce, experience manager, experience platform, managed cloud
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H