← Browse

CVE-2025-53690

Act now ● On CISA KEV — actively exploited

Actively exploited — on the CISA KEV list.

CVSS base
EPSS — probability of exploitation (30 days)
51.1%
98.9th percentile
CISA KEV
Listed
Added 2025-09-04 · patch by 2025-09-25
Weakness / dates
Published — · modified —

Timeline

Description

Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud contain a deserialization of untrusted data vulnerability involving the use of default machine keys. This flaw allows attackers to exploit exposed ASP.NET machine keys to achieve remote code execution.

Official: NVD · CVE.org