The Cybersecurity and Infrastructure Security Agency (CISA) on Sept. 4 put a critical 9.0 Sitecore deserialization bug onto its Known Exploited Vulnerabilities (KEV) catalog once it became clear that it was exploited in the wild.Tracked as CVE-2025-53690, the move to put the flaw on the KEV followed research published by Mandiant last week that certain Sitecore deployments are susceptible to ViewState deserialization attacks because of the reuse of an exposed sample machine key.A ViewState deserialization attack is a cybersecurity exploit that targets web applications built on the ASP.NET framework. It happens when an attacker can manipulate the ViewState data, often leading to severe consequences like remote code execution (RCE) on the server.In its advisory, CISA added that federal agencies must patch the deserialization bug by Thursday, Sept. 25.Mayuresh Dani, security research manager at the Qualys Threat Research Unit, explained that CVE-2025-53690 exists because of the reuse of sample ASP.NET machine keys exposed in Sitecore deployment guides from 2017 and earlier, allowing threat actors to craft malicious ViewState payloads that achieve an RCE.Dani pointed out that Sitecore has experienced deserialization vulnerabilities in the recent past such as CVE-2025-27218 (March 2025) and CVE-2025-34509, CVE-2025-34510, CVE-2025-34511 (June 2025).“What’s concerning is that most of these vulnerabilities have critical deserialization flaws and configuration weaknesses,” said Dani. “Though not extremely popular like other content management software, Sitecore maintains a significant, but niche position in the enterprise market, where multiple well-known companies and some government agencies host their content. Also, based on gathered threat intelligence data, there are more than 22,000 instances exposed publicly.”Desired Effect CEO Evan Dornbush added that the Sitecore vulnerability is a big deal for the same reason all of them are: because attackers found out about it first and defenders didn't. Dornbush said the problem here is not the flaw, but because CVE-2025-53690 is essentially a misconfiguration issue. “The problem is that we, as an industry, continually fail to proactively identify and address issues before they become headlines,” said Dornbush. “We need to flip this power dynamic to empower defenders to get ahead of the curve. We need to start asking how we can get vulnerability intelligence to defenders the moment it's discovered. We also need to ask how we can move from a reactive ‘patch now’ model to a proactive ‘harden before they strike’ model.”
Application security, Patch/Configuration Management, Vulnerability Management, Network Security

Sitecore bug added to CISA’s known exploited vulnerability list

(Adobe Stock)

Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



