← Vulnerability feed

Vulnerability record · CVE-2019-9874 · published 31 May 2019

CVE-2019-9874: Sitecore CMS/XP AntiCSRF module .NET deserialization RCE

SSitecore · Cms

The Sitecore.Security.AntiCSRF module in Sitecore CMS 7.0-7.2 and Sitecore XP 7.5-8.2 deserializes untrusted data from the HTTP POST parameter __CSRFTOKEN. An unauthenticated attacker can send a crafted serialized .NET object to that parameter and achieve remote code execution. The flaw is trivially reachable over the network and requires no credentials or user interaction.

9.8 CVSS 3.1 Critical CISA KEV since 26 Mar 2025 EPSS 84% · top 0.3% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score, v2 7.5
84%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
7References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allows an unauthenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable RCE with CVSS 9.8, KEV listing, and very high EPSS probability makes this an urgent patch-first issue.

What it is

The Sitecore.Security.AntiCSRF module in Sitecore CMS 7.0-7.2 and Sitecore XP 7.5-8.2 deserializes untrusted data from the HTTP POST parameter __CSRFTOKEN. An unauthenticated attacker can send a crafted serialized .NET object to that parameter and achieve remote code execution. The flaw is trivially reachable over the network and requires no credentials or user interaction.

Impact

An attacker gains arbitrary code execution on the Sitecore web server, typically under the application pool identity. This allows full compromise of the CMS host, data theft, and lateral movement into the hosting environment.

Attack surface

Reached over the network via an HTTP POST to the Sitecore application, with the payload placed in the __CSRFTOKEN parameter. No authentication and no user interaction are required, per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

CVE-2019-9874 is listed in CISA KEV (added 2025-03-26) and has an EPSS 30-day probability of 0.837 (99.7th percentile), indicating active exploitation. Public exploit and patch detail is referenced in the Synacktiv advisory, and KEV notes no known ransomware campaign use.

What to do

  • Apply the vendor patch or upgrade to a supported Sitecore release per Sitecore downloads and advisory guidance.
  • If patching is not immediately possible, follow CISA BOD 22-01 guidance and vendor mitigations, or discontinue use of the affected product.
  • Restrict network access to Sitecore instances so they are not directly reachable from untrusted networks.
  • Monitor and block POST requests carrying serialized .NET object payloads in the __CSRFTOKEN parameter at the WAF or reverse proxy.
  • Rotate secrets and review server integrity after any suspected exposure, since RCE implies full host compromise.

Detection

  • Inspect HTTP POST bodies for __CSRFTOKEN values containing .NET serialization markers such as TypeConfuseDelegate, ObjectStateFormatter, or BinaryFormatter signatures.
  • Alert on unexpected child processes spawned by the Sitecore application pool (w3wp.exe), especially cmd.exe, powershell.exe, or net.exe.
  • Review web server and Sitecore logs for anomalous POST requests to endpoints handling the AntiCSRF module.
  • Hunt for outbound connections or file writes from the Sitecore host that do not match normal CMS behavior.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-9874 to the Known Exploited Vulnerabilities catalog on 26 March 2025 as "Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 16 April 2025.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-9874 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-42237Sitecore XP insecure deserialization enables unauthenticated remote code executionSitecore XP 7.5 Initial Release through 8.2 Update-7 deserializes untrusted data, allowing an attacker to run arbitrary commands on the host. No auth…KEVEPSS 98%analysed9.0CVE-2025-53690Sitecore XM/XP untrusted deserialization enables code injectionSitecore Experience Manager and Experience Platform through version 9.0 deserialize untrusted data, allowing an attacker to inject and execute code. …KEVEPSS 51%analysed8.8CVE-2019-9875Sitecore CMS anti-CSRF module .NET deserialization RCEThe anti-CSRF module in Sitecore CMS through 9.1 deserializes untrusted .NET objects supplied in an HTTP POST parameter. An authenticated attacker ca…KEVEPSS 14%analysed9.8CVE-2025-53693Sitecore experience commerce vulnerabilityUse of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Sitecore Sitecore Experience Manager (XM), Siteco…EPSS 15%9.8CVE-2023-35813Sitecore Experience products remote code execution via code injectionMultiple Sitecore products (Experience Manager, Experience Platform, Experience Commerce, and Managed Cloud) through version 10.3 contain a code inje…EPSS 87%analysed9.8CVE-2023-27068Sitecore experience platform deserialization of untrusted data vulnerabilityDeserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code via ValidationResult.asp…EPSS 1.7%8.8CVE-2025-53691Sitecore experience commerce deserialization of untrusted data vulnerabilityDeserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Remote Code Execution (…EPSS 1.6%8.8CVE-2025-34510Sitecore experience commerce relative path traversal vulnerabilitySitecore Experience Manager (XM), Experience Platform (XP), and Experience Commerce (XC) versions 9.0 through 9.3 and 10.0 through 10.4 are affected …EPSS 24%

Source: NIST National Vulnerability Database (record CVE-2019-9874), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.