← Vulnerability feed

Vulnerability record · CVE-2025-53690 · published 3 September 2025

CVE-2025-53690: Sitecore XM/XP untrusted deserialization enables code injection

SSitecore · Experience Commerce

Sitecore Experience Manager and Experience Platform through version 9.0 deserialize untrusted data, allowing an attacker to inject and execute code. The flaw is remotely reachable without authentication or user interaction, and it is listed in CISA KEV, so it warrants urgent attention.

9.0 CVSS 3.1 Critical CISA KEV since 4 Sep 2025 EPSS 51% · top 1.1% CWE-502 · Deserialization of untrusted data
9.0CVSS 3.1 base score
51%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
4Affected product versions listed by NVD
3References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (XM): through 9.0; Experience Platform (XP): through 9.0.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityIt is a remotely reachable, unauthenticated code injection flaw with a CVSS of 9.0, active KEV listing and high EPSS probability.

What it is

Sitecore Experience Manager and Experience Platform through version 9.0 deserialize untrusted data, allowing an attacker to inject and execute code. The flaw is remotely reachable without authentication or user interaction, and it is listed in CISA KEV, so it warrants urgent attention.

Impact

An attacker can execute arbitrary code in the context of the Sitecore application, potentially leading to full compromise of the host and its data.

Attack surface

Reachable over the network via the affected Sitecore application; the CVSS vector indicates no privileges or user interaction are required, though attack complexity is rated high.

Exploitation

CVE-2025-53690 is in CISA KEV with a 2025-09-25 remediation due date, and EPSS shows a 30-day probability of about 51 percent; a public exploit reference exists.

What to do

  • Apply the vendor mitigation or patch from Sitecore advisory KB1003865 immediately.
  • If patching is not possible, follow CISA BOD 22-01 guidance for cloud services or discontinue use of the affected product.
  • Restrict network access to Sitecore management and application endpoints to trusted sources.
  • Monitor for and block deserialization payloads targeting Sitecore ViewState and related handlers.
  • Review Sitecore deployments for version 9.0 and earlier and prioritize internet-facing instances.

Detection

  • Monitor application and web server logs for ViewState deserialization errors or unexpected object graph activity.
  • Alert on suspicious child processes spawned by the Sitecore application or its web server.
  • Hunt for known deserialization gadget signatures in HTTP requests to Sitecore endpoints.
  • Correlate outbound network connections from Sitecore hosts with unusual destinations.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-53690 to the Known Exploited Vulnerabilities catalog on 4 September 2025 as "Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 25 September 2025.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-53690 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-42237Sitecore XP insecure deserialization enables unauthenticated remote code executionSitecore XP 7.5 Initial Release through 8.2 Update-7 deserializes untrusted data, allowing an attacker to run arbitrary commands on the host. No auth…KEVEPSS 98%analysed9.8CVE-2019-9874Sitecore CMS/XP AntiCSRF module .NET deserialization RCEThe Sitecore.Security.AntiCSRF module in Sitecore CMS 7.0-7.2 and Sitecore XP 7.5-8.2 deserializes untrusted data from the HTTP POST parameter __CSRF…KEVEPSS 84%analysed9.8CVE-2025-53693Sitecore experience commerce vulnerabilityUse of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Sitecore Sitecore Experience Manager (XM), Siteco…EPSS 15%9.8CVE-2023-35813Sitecore Experience products remote code execution via code injectionMultiple Sitecore products (Experience Manager, Experience Platform, Experience Commerce, and Managed Cloud) through version 10.3 contain a code inje…EPSS 87%analysed9.8CVE-2023-27068Sitecore experience platform deserialization of untrusted data vulnerabilityDeserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code via ValidationResult.asp…EPSS 1.7%8.8CVE-2025-53691Sitecore experience commerce deserialization of untrusted data vulnerabilityDeserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Remote Code Execution (…EPSS 1.6%8.8CVE-2025-34510Sitecore experience commerce relative path traversal vulnerabilitySitecore Experience Manager (XM), Experience Platform (XP), and Experience Commerce (XC) versions 9.0 through 9.3 and 10.0 through 10.4 are affected …EPSS 24%8.8CVE-2025-34511Sitecore experience commerce unrestricted file upload vulnerabilitySitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through version 7.0 is vulnerable to an u…EPSS 30%

Source: NIST National Vulnerability Database (record CVE-2025-53690), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.