CVE-2025-53690: Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability
Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (XM): through 9.0; Experience Platform (XP): through 9.0.
Other sources
Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud contain a deserialization of untrusted data vulnerability involving the use of default machine keys. This flaw allows attackers to exploit exposed ASP.NET machine keys to achieve remote code execution.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Sitecore Experience Manager (XM)from your environment.Discontinue use of the product if mitigations are unavailable.
- Remove
Remove
Sitecore Experience Platform (XP)from your environment.Discontinue use of the product if mitigations are unavailable.
- Remove
Remove
Experience Commerce (XC)from your environment.Discontinue use of the product if mitigations are unavailable.
- Remove
Remove
Managed Cloudfrom your environment.Discontinue use of the product if mitigations are unavailable.
- Configuration
Replace default machineKey entries (validationKey and decryptionKey) in web.config with unique, securely generated values and protect them from exposure.
ASP.NET machineKey validationKey / decryptionKey = Replace default keys with unique, securely generated non-default values and ensure they are not exposed - Compensating control
Follow applicable BOD 22-01 guidance for cloud services.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53690?
CVE-2025-53690 has a critical severity level due to its potential for code injection via deserialization of untrusted data.
Which software versions are affected by CVE-2025-53690?
CVE-2025-53690 affects Sitecore Experience Manager (XM) up to version 9.0 and Sitecore Experience Platform (XP) up to version 9.0.
How do I fix CVE-2025-53690?
To mitigate CVE-2025-53690, upgrade Sitecore Experience Manager and Sitecore Experience Platform to versions beyond 9.0 where the vulnerability is patched.
What type of vulnerability is CVE-2025-53690?
CVE-2025-53690 is a deserialization of untrusted data vulnerability that allows for code injection.
Can CVE-2025-53690 be exploited remotely?
Yes, CVE-2025-53690 can potentially be exploited remotely due to the nature of the deserialization vulnerability in the affected software.