← Vulnerability feed

Vulnerability record · CVE-2021-42237 · published 5 November 2021

CVE-2021-42237: Sitecore XP insecure deserialization enables unauthenticated remote code execution

SSitecore · Experience Platform

Sitecore XP 7.5 Initial Release through 8.2 Update-7 deserializes untrusted data, allowing an attacker to run arbitrary commands on the host. No authentication or special configuration is needed, so any reachable instance is exposed. The flaw is tracked in CISA KEV with known ransomware use, making it a high-value target for both initial access and destructive campaigns.

9.8 CVSS 3.1 Critical CISA KEV since 25 Mar 2022 Known ransomware use EPSS 98% · top 0.1% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score, v2 10.0
98%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References, 2 tagged exploit
9 Jul 2026Last modified by NVD

Description

Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required to exploit this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable RCE with a 9.8 CVSS score, KEV listing, ransomware use and near-maximum EPSS probability.

What it is

Sitecore XP 7.5 Initial Release through 8.2 Update-7 deserializes untrusted data, allowing an attacker to run arbitrary commands on the host. No authentication or special configuration is needed, so any reachable instance is exposed. The flaw is tracked in CISA KEV with known ransomware use, making it a high-value target for both initial access and destructive campaigns.

Impact

An attacker gains remote command execution on the Sitecore server, which typically means full control of the web application, its data and the underlying host. From there they can pivot into internal networks, steal credentials or deploy ransomware.

Attack surface

Reachable over the network via the Sitecore XP web interface; the CVSS vector shows AV:N/PR:N/UI:N, so no credentials and no user interaction are required. Any internet- or intranet-exposed instance in the affected version range is a candidate.

Exploitation

Listed in CISA KEV since 2022-03-25 with known ransomware campaign use, and EPSS 30-day probability is 0.979 (99.9th percentile). Public exploit references exist, so exploitation is active and widespread.

What to do

  • Apply the vendor update per Sitecore KB1000776; upgrade off the affected 7.5 to 8.2 Update-7 range.
  • If patching cannot be done immediately, remove or restrict network access to the Sitecore XP instance, especially from the internet.
  • Place the instance behind a WAF or reverse proxy with rules targeting deserialization payloads, understanding this is only a stopgap.
  • Rotate credentials and secrets stored on or reachable from the Sitecore host, and review for signs of prior compromise.
  • Monitor CISA KEV guidance and confirm the due date of 2022-04-15 has been met for your environment.

Detection

  • Hunt web server and Sitecore logs for POST requests to Sitecore endpoints containing serialized .NET payload markers or unusually large binary bodies.
  • Alert on child processes spawned by the Sitecore/IIS worker process (w3wp.exe), such as cmd.exe, powershell.exe or net.exe.
  • Monitor for outbound connections from the Sitecore host to unfamiliar IPs, consistent with post-exploitation or ransomware staging.
  • Review file system and registry changes on the Sitecore server for webshells or new scheduled tasks.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-42237 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "Sitecore XP Remote Command Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-42237 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-9874Sitecore CMS/XP AntiCSRF module .NET deserialization RCEThe Sitecore.Security.AntiCSRF module in Sitecore CMS 7.0-7.2 and Sitecore XP 7.5-8.2 deserializes untrusted data from the HTTP POST parameter __CSRF…KEVEPSS 84%analysed9.0CVE-2025-53690Sitecore XM/XP untrusted deserialization enables code injectionSitecore Experience Manager and Experience Platform through version 9.0 deserialize untrusted data, allowing an attacker to inject and execute code. …KEVEPSS 51%analysed9.8CVE-2025-53693Sitecore experience commerce vulnerabilityUse of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Sitecore Sitecore Experience Manager (XM), Siteco…EPSS 15%9.8CVE-2023-35813Sitecore Experience products remote code execution via code injectionMultiple Sitecore products (Experience Manager, Experience Platform, Experience Commerce, and Managed Cloud) through version 10.3 contain a code inje…EPSS 87%analysed9.8CVE-2023-27068Sitecore experience platform deserialization of untrusted data vulnerabilityDeserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code via ValidationResult.asp…EPSS 1.7%8.8CVE-2025-53691Sitecore experience commerce deserialization of untrusted data vulnerabilityDeserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Remote Code Execution (…EPSS 1.6%8.8CVE-2025-34510Sitecore experience commerce relative path traversal vulnerabilitySitecore Experience Manager (XM), Experience Platform (XP), and Experience Commerce (XC) versions 9.0 through 9.3 and 10.0 through 10.4 are affected …EPSS 24%8.8CVE-2025-34511Sitecore experience commerce unrestricted file upload vulnerabilitySitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through version 7.0 is vulnerable to an u…EPSS 30%

Source: NIST National Vulnerability Database (record CVE-2021-42237), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.