Vulnerability record · CVE-2019-9874 · published 31 May 2019
CVE-2019-9874: Sitecore CMS/XP AntiCSRF module .NET deserialization RCE
SSitecore · Cms
The Sitecore.Security.AntiCSRF module in Sitecore CMS 7.0-7.2 and Sitecore XP 7.5-8.2 deserializes untrusted data from the HTTP POST parameter __CSRFTOKEN. An unauthenticated attacker can send a crafted serialized .NET object to that parameter and achieve remote code execution. The flaw is trivially reachable over the network and requires no credentials or user interaction.
Description
Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allows an unauthenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable RCE with CVSS 9.8, KEV listing, and very high EPSS probability makes this an urgent patch-first issue.
What it is
The Sitecore.Security.AntiCSRF module in Sitecore CMS 7.0-7.2 and Sitecore XP 7.5-8.2 deserializes untrusted data from the HTTP POST parameter __CSRFTOKEN. An unauthenticated attacker can send a crafted serialized .NET object to that parameter and achieve remote code execution. The flaw is trivially reachable over the network and requires no credentials or user interaction.
Impact
An attacker gains arbitrary code execution on the Sitecore web server, typically under the application pool identity. This allows full compromise of the CMS host, data theft, and lateral movement into the hosting environment.
Attack surface
Reached over the network via an HTTP POST to the Sitecore application, with the payload placed in the __CSRFTOKEN parameter. No authentication and no user interaction are required, per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
CVE-2019-9874 is listed in CISA KEV (added 2025-03-26) and has an EPSS 30-day probability of 0.837 (99.7th percentile), indicating active exploitation. Public exploit and patch detail is referenced in the Synacktiv advisory, and KEV notes no known ransomware campaign use.
What to do
- Apply the vendor patch or upgrade to a supported Sitecore release per Sitecore downloads and advisory guidance.
- If patching is not immediately possible, follow CISA BOD 22-01 guidance and vendor mitigations, or discontinue use of the affected product.
- Restrict network access to Sitecore instances so they are not directly reachable from untrusted networks.
- Monitor and block POST requests carrying serialized .NET object payloads in the __CSRFTOKEN parameter at the WAF or reverse proxy.
- Rotate secrets and review server integrity after any suspected exposure, since RCE implies full host compromise.
Detection
- Inspect HTTP POST bodies for __CSRFTOKEN values containing .NET serialization markers such as TypeConfuseDelegate, ObjectStateFormatter, or BinaryFormatter signatures.
- Alert on unexpected child processes spawned by the Sitecore application pool (w3wp.exe), especially cmd.exe, powershell.exe, or net.exe.
- Review web server and Sitecore logs for anomalous POST requests to endpoints handling the AntiCSRF module.
- Hunt for outbound connections or file writes from the Sitecore host that do not match normal CMS behavior.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-9874 to the Known Exploited Vulnerabilities catalog on 26 March 2025 as "Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 16 April 2025.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://dev.sitecore.net/Downloads.aspx | ProductVendor Advisory |
| https://www.synacktiv.com/blog.html | Third Party Advisory |
| https://www.synacktiv.com/ressources/advisories/Sitecore_CSRF_deserialize_RCE.pdf | ExploitPatchThird Party Advisory |
| https://dev.sitecore.net/Downloads.aspx | ProductVendor Advisory |
| https://www.synacktiv.com/blog.html | Third Party Advisory |
| https://www.synacktiv.com/ressources/advisories/Sitecore_CSRF_deserialize_RCE.pdf | ExploitPatchThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-9874 | US Government Resource |
Track CVE-2019-9874 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-9874), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.