EXPOSURES › CVE-2019-10068
CVE-2019-10068
HIGH ⌖ ON CISA KEV · EXPLOITEDKentico Xperience suffered an unpatched deserialization vulnerability enabling unauthenticated remote code execution, now on CISA's KEV list.
Kentico Xperience failed to validate security headers, allowing unauthenticated remote code execution via deserialization of untrusted data. This is a critical failure for DIB organizations because it represents a known, actively exploited vulnerability that bypasses authentication entirely, directly impacting compliance with CMMC/NIST 800-171 requirements for patch management and access control. Organizations must immediately verify their Kentico deployments, apply patches, and assess for compromise.
Shame score — A known, actively exploited vulnerability on CISA's KEV list that enables unauthenticated remote code execution demonstrates severe negligence in patch management and security header validation.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Kentico contains a failure to validate security headers. This deserialization can led to unauthenticated remote code execution.