• News/
  • https://www.theregister.com/2025/09/04/unknown_miscreants_snooping_around_sitecore/

Attackers snooping around Sitecore, dropping malware via public sample keys

The Register
·
Jessica Lyons
·
Published Sep 4, 2025
·
Updated

Unknown miscreants are exploiting a configuration vulnerability in multiple Sitecore products to achieve remote code execution via a publicly exposed key and deploy snooping malware on infected machines. All versions of Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud remain "potentially impacted" by CVE-2025-53690, a ViewState deserialization vulnerability, if they are deployed in a multi-instance mode with customer-managed static machine keys, the business software provider warned in a Wednesday security bulletin. The bug is due to a configuration issue - not a software hole - and affects customers using the sample key provided with deployment instructions for Sitecore XP 9.0 or earlier and Sitecore Active Directory 1.4 and earlier versions. Updated deployments automatically generate a random machine key. If you're stuck with one of the sample keys from Sitecore's old docs instead of generating your own, treat your install as vulnerable and rotate those keys now. "Successful exploitation of the related vulnerability might lead to remote code execution and non-authorized access to information," the vendor noted. Plus, it appears that criminals seized upon these publicly documented keys to remotely execute code and snoop around exposed instances before Sitecore issued its guidance. On Wednesday, in conjunction with Sitecore's bulletin, Mandiant published its own account of an attack disrupted midway, during which the atta...

Read full article

Affected Software

5 affected components
Sitecore Experience Manager
Sitecore Experience Platform
Sitecore Experience Commerce
Sitecore Managed Cloud
Sitecore Active Directory=1.4
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a security vulnerability in Sitecore products that allows attackers to exploit a publicly exposed key for remote code execution.

2

What security implications are discussed?

The article highlights the risk of malware deployment on infected machines due to the configuration vulnerability in Sitecore products.

3

What products or software are affected?

The affected products include Sitecore Experience Manager, Sitecore Experience Platform, Sitecore Experience Commerce, Sitecore Managed Cloud, and Sitecore Active Directory.

4

How are attackers exploiting this vulnerability?

Attackers are using publicly exposed sample keys to gain access to Sitecore systems and deploy malware.

5

What can organizations do to protect themselves from this vulnerability?

Organizations should ensure proper configuration management and review the security of their Sitecore installations to mitigate risks associated with this vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203