Deserialization Vulnerability in Sitecore Experience Manager and Experience Platform
CVE-2025-53690

9CRITICAL

Key Information:

Vendor

Sitecore

Vendor
CVE Published:
3 September 2025

What is CVE-2025-53690?

A deserialization vulnerability in Sitecore Experience Manager (XM) and Sitecore Experience Platform (XP) could allow attackers to exploit untrusted data, potentially leading to unauthorized code execution. Applications using affected versions are at risk, making it essential for users to ensure they are on updated releases and to implement appropriate security measures.

Affected Version(s)

Experience Manager (XM) 0 <= 9.0

Experience Platform (XP) 0 <= 9.0

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mandiant Threat Defense
.
CVE-2025-53690 : Deserialization Vulnerability in Sitecore Experience Manager and Experience Platform