Skip to content
COOEY

EXPOSURES › CVE-2019-10068

CVE-2019-10068

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-10068 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatched

Kentico Xperience suffered an unpatched deserialization vulnerability enabling unauthenticated remote code execution, now on CISA's KEV list.

Kentico Xperience failed to validate security headers, allowing unauthenticated remote code execution via deserialization of untrusted data. This is a critical failure for DIB organizations because it represents a known, actively exploited vulnerability that bypasses authentication entirely, directly impacting compliance with CMMC/NIST 800-171 requirements for patch management and access control. Organizations must immediately verify their Kentico deployments, apply patches, and assess for compromise.

Shame score — A known, actively exploited vulnerability on CISA's KEV list that enables unauthenticated remote code execution demonstrates severe negligence in patch management and security header validation.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Kentico contains a failure to validate security headers. This deserialization can led to unauthenticated remote code execution.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.