CVE-2025-53690 is a critical deserialization of untrusted data vulnerability in Sitecore Experience Manager (XM) and Experience Platform (XP) versions through 9.0, allowing for remote code injection. With a CVSS score of 9.0, this flaw presents a severe risk due to its network-based attack vector, high impact on confidentiality, integrity, and availability, and low attack complexity. This vulnerability is actively exploited in the wild, as confirmed by its presence in the KEV catalog and reports of China-linked APT groups leveraging it for initial access. While no public exploit code is immediately available via Metasploit, Nuclei, or ExploitDB, the high volume of community discussion and media coverage underscores its significant threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.0CPE matchmatch criteria | cpe:2.3:a:sitecore:experience_commerce:*:*:*:*:*:*:*:* | ||
<= 9.0CPE matchmatch criteria | cpe:2.3:a:sitecore:experience_manager:*:*:*:*:*:*:*:* | ||
<= 9.0CPE matchmatch criteria | cpe:2.3:a:sitecore:experience_platform:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:sitecore:managed_cloud:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.4 Reddit, 1.3 Bluesky, 0.9 Mastodon, and 2.3 GitHub mentions.
The average CVE in this peer group has 0.8 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.