Vulnerability record · CVE-2025-53690 · published 3 September 2025
CVE-2025-53690: Sitecore XM/XP untrusted deserialization enables code injection
SSitecore · Experience Commerce
Sitecore Experience Manager and Experience Platform through version 9.0 deserialize untrusted data, allowing an attacker to inject and execute code. The flaw is remotely reachable without authentication or user interaction, and it is listed in CISA KEV, so it warrants urgent attention.
Description
Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (XM): through 9.0; Experience Platform (XP): through 9.0.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityIt is a remotely reachable, unauthenticated code injection flaw with a CVSS of 9.0, active KEV listing and high EPSS probability.
What it is
Sitecore Experience Manager and Experience Platform through version 9.0 deserialize untrusted data, allowing an attacker to inject and execute code. The flaw is remotely reachable without authentication or user interaction, and it is listed in CISA KEV, so it warrants urgent attention.
Impact
An attacker can execute arbitrary code in the context of the Sitecore application, potentially leading to full compromise of the host and its data.
Attack surface
Reachable over the network via the affected Sitecore application; the CVSS vector indicates no privileges or user interaction are required, though attack complexity is rated high.
Exploitation
CVE-2025-53690 is in CISA KEV with a 2025-09-25 remediation due date, and EPSS shows a 30-day probability of about 51 percent; a public exploit reference exists.
What to do
- Apply the vendor mitigation or patch from Sitecore advisory KB1003865 immediately.
- If patching is not possible, follow CISA BOD 22-01 guidance for cloud services or discontinue use of the affected product.
- Restrict network access to Sitecore management and application endpoints to trusted sources.
- Monitor for and block deserialization payloads targeting Sitecore ViewState and related handlers.
- Review Sitecore deployments for version 9.0 and earlier and prioritize internet-facing instances.
Detection
- Monitor application and web server logs for ViewState deserialization errors or unexpected object graph activity.
- Alert on suspicious child processes spawned by the Sitecore application or its web server.
- Hunt for known deserialization gadget signatures in HTTP requests to Sitecore endpoints.
- Correlate outbound network connections from Sitecore hosts with unusual destinations.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-53690 to the Known Exploited Vulnerabilities catalog on 4 September 2025 as "Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 25 September 2025.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://cloud.google.com/blog/topics/threat-intelligence/viewstate-deserialization-zero-day-vulnerability | ExploitThird Party Advisory |
| https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1003865 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-53690 | US Government Resource |
Track CVE-2025-53690 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-53690), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.