Junglewise Threat Intelligence

CVE-2025-53690: Sitecore Multiple Products deserialization of untrusted data

CVE-2025-53690 · Severity: critical · CVSS 9 · Exploited in the wild · Published 2025-09-04

Technologies: Apple Multiple Products, Sitecore Experience Platform (XP). Vendors: Sitecore, Apple.

Executive brief

Sitecore Experience Manager and related products, which are used by organizations to manage digital content and customer experiences, contain a critical security flaw. This vulnerability allows an attacker to take full control of the server by exploiting default security keys used to protect web session data. This issue has been observed being used in active attacks, potentially leading to data theft or complete service disruption.

Technical details

A deserialization of untrusted data vulnerability (CWE-502) exists in multiple Sitecore products due to the use of default ASP.NET machine keys. An unauthenticated attacker can leverage these known keys to craft malicious ViewState payloads. When the server attempts to deserialize this untrusted data, it results in remote code execution (RCE) with the privileges of the web application. The vulnerability is particularly severe as it has been exploited in the wild as a zero-day. Organizations are advised to rotate their machine keys and apply vendor-provided mitigations immediately.

Affected products

  • Sitecore Experience Manager (XM) through 9.0
  • Sitecore Experience Platform (XP) through 9.0
  • Sitecore Experience Commerce (XC) through 9.0
  • Sitecore Managed Cloud All versions

Timeline

  • 2025-09-03: disclosed: Initial disclosure by Wiz and Sitecore
  • 2025-09-04: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2025-09-04: advisory: NVD publication date

Related threats