EXPOSURES › CVE-2025-53690
CVE-2025-53690
HIGH ⌖ ON CISA KEV · EXPLOITEDSitecore's deserialization flaw allowed remote code execution via untrusted data processing
Sitecore's Experience Manager, Experience Platform, Experience Commerce, and Managed Cloud products had a vulnerability that allowed attackers to exploit exposed ASP.NET machine keys for remote code execution. This was actively exploited in the wild, posing a high risk to DIB organizations.
Shame score — Active exploitation in the wild indicates negligence in security practices.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud contain a deserialization of untrusted data vulnerability involving the use of default machine keys. This flaw allows attackers to exploit exposed ASP.NET machine keys to achieve remote code execution.