ZeroHour

CVE-2025-53690

KEV PoC large

Unauthenticated ViewState Deserialization RCE in Sitecore XM/XP

CISA: Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability

CVSS 3.1
9.0 critical
EPSS
51%p99
Published
()
KEV added
AI analysis

CVE-2025-53690 is a critical (CVSS 9.0) deserialization-of-untrusted-data flaw (CWE-502) in Sitecore Experience Manager (XM) and Experience Platform (XP) through version 9.0 that enables unauthenticated code injection. Public threat reporting (Google Cloud/Mandiant) and news coverage tie the flaw to ASP.NET ViewState deserialization performed using exposed (default or leaked) ASP.NET machine keys, so a remote attacker who can reach a Sitecore site can submit a crafted, signed ViewState payload that is deserialized server-side, resulting in remote code execution. A successful unauthenticated attacker gains arbitrary code execution on the web server with the scope-changed (S:C) impact of high confidentiality, integrity and availability loss. Organizations running internet-facing Sitecore XM/XP deployments — including Experience Commerce and Managed Cloud deployments — are in scope. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-09-04, and reporting links the activity to a China-linked APT (UAT-8837) targeting North American critical infrastructure.

What to do: Apply Sitecore's security updates to all affected XM/XP deployments (through 9.0) and follow the vendor's mitigations as required by CISA KEV/BOD 22-01, or discontinue use if patching is not possible. Per the public reporting, rotate any exposed or default ASP.NET machineKey values (e.g., in web.config) on internet-facing Sitecore servers, since exposed machine keys enable the ViewState deserialization attacks. Inventory internet-exposed Sitecore instances and review them for signs of compromise.

Affected
Sitecore Experience Manager (XM)through 9.0
Sitecore Experience Platform (XP)through 9.0
Sitecore Experience Commerce
Sitecore Managed Cloud
Estimated exposure
largetens of thousands of internet-exposed Sitecore deployments (order of magnitude ~10^4–10^5) — Sitecore is an enterprise CMS/commerce platform with thousands of large-organization customers, and public internet scans have repeatedly surfaced tens of thousands of internet-facing Sitecore instances, so the plausible exposure is on the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (XM): through 9.0; Experience Platform (XP): through 9.0.

CISA Known Exploited Vulnerability
Affected
Sitecore Multiple Products
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
sitecore
Products
experience commerce, experience manager, experience platform, managed cloud
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news