Unrated severityCISA KEVNVD Advisory· Published Sep 3, 2025· Updated Feb 26, 2026
Sitecore Products ViewState Deserialization Vulnerability
CVE-2025-53690
Description
Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (XM): through 9.0; Experience Platform (XP): through 9.0.
Affected products
2- Sitecore/Experience Manager (XM)v5Range: 0
- Sitecore/Experience Platform (XP)v5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.