CVE-2025-53690
⚠ KEVEPSS 5.2%Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability
Added to CISA KEV: 9/4/2025
Description
Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud contain a deserialization of untrusted data vulnerability involving the use of default machine keys. This flaw allows attackers to exploit exposed ASP.NET machine keys to achieve remote code execution.
Affected packages (0)
No package mapping in OSV.