Critical ViewState deserialization vulnerability in Sitecore Experience Manager/Platform allowing remote code execution. Actively exploited in the wild since December 2024, affecting internet-facing Sitecore deployments using default sample machine keys.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2025-09-03
Added to CISA KEV: 2025-09-04 1 DAY BETWEEN CVE AND KEV
An active ViewState deserialization attack affecting Sitecore products, where attackers achieved remote code execution.
A threat actor is leveraging a zero-day vulnerability (CVE-2025-53690) to breach internet-facing, on-prem deployments of Sitecore solutions.
CVE-2025-53690, a critical Sitecore flaw (CVSS 9.0), exploited since Dec 2024, enables RCE and data theft.
Information Technology Laboratory National Vulnerability DatabaseVulnerabilities
The vulnerability , tracked as CVE-2025-53690 , carries a CVSS score of 9.0 out of a maximum of 10.0, indicating critical severity.Apple Patches CVE-2025-43300 Zero-Day in iOS, iPadOS, and macOS Exploited in Targeted Attacks.