U.S. CISA adds Sitecore, Android, and Linux flaws to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-38352 | Actively Exploited TOCTOU Race Condition in Linux Kernel POSIX CPU Timers CVE-2025-38352 is a time-of-check to time-of-use (TOCTOU) race condition (CWE-367) in the Linux kernel's POSIX CPU timers subsystem: when an exiting non-auto-reaping task has passed exit_notify() and handles CPU timers from interrupt context, it can be reaped by its parent or debugger right after unlock_task_sighand(), so a concurrent posix_cpu_timer_del() cannot detect that the timer is firing (cpu_timer_task_rcu() and/or lock_task_sighand() fail). A local attacker with low privileges who can manipulate POSIX CPU timers on such a task can win this race window, with high impact to confidentiality, integrity, and availability (CVSS 3.1: 7.8, local vector, no user interaction). Any system running an affected Linux kernel is exposed, including Debian GNU/Linux deployments and Android devices built on the kernel; practical reachability is limited where CONFIG_POSIX_CPU_TIMERS_TASK_WORK=y routes timer handling through task work instead of IRQ context. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-09-04 and Google shipped it as an actively exploited fix in the September 2025 Android security update; EPSS currently estimates a 1.3% probability of exploitation within 30 days (68th percentile), and a public proof-of-concept is available. Do: Apply updated kernel packages from your distribution (Debian and other vendors ship the upstream posix-cpu-timers fix) and install Google's September 2025 Android security patch on Android devices; CISA KEV listing requires federal agencies to apply vendor mitigations or discontinue use per BOD 22-01. Because exploitation requires local code execution, prioritize multi-tenant servers, build/CI hosts, and devices where untrusted users or apps run local code. A public proof-of-concept (github.com/farazsth98/chronomaly) is available for validation testing. | 7.8 | 1% | KEV PoC ×2 |
| massbillions of devices (the Linux kernel underpins roughly 3+ billion active Android devices and the majority of server/cloud workloads, though per-bug… | |
| CVE-2025-48543 | Use-After-Free in Android Runtime Enables Sandbox Escape and Local Privilege Escalation CVE-2025-48543 is a use-after-free (CWE-416) in the Android Runtime that exists in multiple code locations and allows an attacker who has already achieved code execution inside the Chrome sandbox to escape and attack the Android system_server process. The trigger requires only local access to the vulnerable component, with no additional execution privileges and no user interaction needed for exploitation. A successful attacker gains local escalation of privilege in the Android system server, making the bug especially useful as a privilege-escalation link in exploit chains against Android devices. Any Android device from Google's platform is in scope per CISA's listing (vendor: Google, product: Android, component: Android Runtime); specific affected version ranges are not enumerated in the source data. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-09-04 and Google's related headlines indicate it is being actively exploited in the wild; EPSS currently estimates only a 0.5% probability of exploitation in the next 30 days, and ransomware use is listed as unknown. Do: Apply Google's Android security updates (September 2025 security bulletin patch level or later) as soon as they are available for your devices, since this flaw is listed in CISA's KEV and reported as exploited in the wild; per KEV required action, federal agencies must follow BOD 22-01 timelines or discontinue use if mitigations are unavailable. Use MDM/EDR tooling to verify device security patch levels, and note that because this is a sandbox-escape-to-system_server bug, it is most dangerous when chained with a browser/renderer exploit, so keeping Chrome/WebView current matters as well. | 8.8 | <1% | KEV |
| masson the order of billions of devices (Android runs on roughly 3 billion+ active devices worldwide, and the Android Runtime/system_server component is present on… | |
| CVE-2025-53690 | Unauthenticated ViewState Deserialization RCE in Sitecore XM/XP CVE-2025-53690 is a critical (CVSS 9.0) deserialization-of-untrusted-data flaw (CWE-502) in Sitecore Experience Manager (XM) and Experience Platform (XP) through version 9.0 that enables unauthenticated code injection. Public threat reporting (Google Cloud/Mandiant) and news coverage tie the flaw to ASP.NET ViewState deserialization performed using exposed (default or leaked) ASP.NET machine keys, so a remote attacker who can reach a Sitecore site can submit a crafted, signed ViewState payload that is deserialized server-side, resulting in remote code execution. A successful unauthenticated attacker gains arbitrary code execution on the web server with the scope-changed (S:C) impact of high confidentiality, integrity and availability loss. Organizations running internet-facing Sitecore XM/XP deployments — including Experience Commerce and Managed Cloud deployments — are in scope. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-09-04, and reporting links the activity to a China-linked APT (UAT-8837) targeting North American critical infrastructure. Do: Apply Sitecore's security updates to all affected XM/XP deployments (through 9.0) and follow the vendor's mitigations as required by CISA KEV/BOD 22-01, or discontinue use if patching is not possible. Per the public reporting, rotate any exposed or default ASP.NET machineKey values (e.g., in web.config) on internet-facing Sitecore servers, since exposed machine keys enable the ViewState deserialization attacks. Inventory internet-exposed Sitecore instances and review them for signs of compromise. | 9.0 | 51% | KEV PoC |
| largetens of thousands of internet-exposed Sitecore deployments (order of magnitude ~10^4–10^5) |
Full article344 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
September 05, 2025

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Sitecore, Android, and Linux flaws to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Sitecore, Android, and Linux flaws to its Known Exploited Vulnerabilities (KEV) catalog.
Below are the descriptions for these flaws:
- CVE-2025-38352 Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability
- CVE-2025-48543 Android Runtime Unspecified Vulnerability
- CVE-2025-53690 Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability
This week, Google released security updates to address 120 Android vulnerabilities as part of Android Security Bulletin – September 2025. Two of these vulnerabilities have been exploited in targeted attacks.
“There are indications that the following may be under limited, targeted exploitation.
- CVE-2025-38352 (CVSS score: 7.4) – A privilege escalation flaw in the Linux Kernel component
- CVE-2025-48543 (CVSS score: N/A) – A privilege escalation flaw in the Android Runtime component
Google warned that the two flaws allow local privilege escalation without extra permissions or user interaction.
Benoît Sevens of Google’s Threat Analysis Group (TAG) discovered the flaw CVE-2025-38352, a circumstance that suggests that it may have been exploited by advanced threat actors in spyware attacks.
As usual, the tech giant did not disclose technical details on their exploitation.
The third vulnerability added to CISA’s KeV catalog is CVE-2025-53690 (CVSS score: 7.4). The issue is a deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) that allows code injection. This vulnerability impacts Experience Manager (XM): through 9.0; Experience Platform (XP): through 9.0.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the vulnerabilities by September 25, 2025.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, cisa)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/181924/breaking-news/u-s-cisa-adds-sitecore-android-and-linux-flaws-to-its-known-exploited-vulnerabilities-catalog.html