CVE-2025-53690
Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability
Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (XM): through 9.0.
Experience Platform (XP): through 9.0.
CRITICAL · CVSS 9
⚠ CISA KEV
EPSS 0.05153
Act now
- Listed on CISA KEV (known exploited in the wild)
- SSVC exploitation status: active
- EPSS percentile: top 10% of all CVEs by exploitation likelihood
- Public exploit or PoC is available
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0