CVE-2025-53690
Act now ● On CISA KEV — actively exploited
Actively exploited — on the CISA KEV list.
CVSS base
—
EPSS — probability of exploitation (30 days)
51.1%
98.9th percentile
CISA KEV
Listed
Added 2025-09-04 · patch by 2025-09-25
Weakness / dates
—
Published — · modified —
Description
Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud contain a deserialization of untrusted data vulnerability involving the use of default machine keys. This flaw allows attackers to exploit exposed ASP.NET machine keys to achieve remote code execution.