EXPOSURES › CVE-2021-42237
CVE-2021-42237
CRITICAL ⌖ ON CISA KEV · EXPLOITEDSitecore XP's insecure deserialization allowed for remote code execution, actively exploited in ransomware attacks, impacting DIB organizations using the platform for content management and web applications.
A critical insecure deserialization vulnerability (CVE-2021-42237) in Sitecore XP enabled remote code execution, and was actively exploited, potentially leading to ransomware deployment and data compromise. DIB organizations utilizing Sitecore XP must immediately patch and review their security posture to avoid exploitation and maintain CMMC compliance.
Shame score — The vulnerability's exploitation in ransomware attacks highlights a significant failure in Sitecore's secure development practices and poses a serious risk to DIB clients.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution.