CVE-2025-53690
Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (XM): through 9.0; Experience Platform (XP): through 9.0.
- Published Sep 3, 2025
- CVSS 9.0 critical
- 51.1% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
- Public exploit code is available
Affected software
In the news
- APT and financial attacks on industrial organizations in Q1 2026 Kaspersky ICS CERT ·
- VulnCheck Research Highlights: October 2025 VulnCheck Blog ·