CVE-2025-53690
Description
Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (XM): through 9.0; Experience Platform (XP): through 9.0.
Summary dbcve.org
A deserialization of untrusted data vulnerability in Sitecore Experience Manager (XM) and Experience Platform (XP) allows attackers to inject malicious code through unsafe deserialization. This affects all versions through 9.0, enabling remote code execution due to the lack of proper validation on deserialized data.
Mitigation
Upgrade to a patched version of Sitecore XP/XM beyond 9.0, or implement input validation and secure serialization practices on data streams entering the deserialization endpoints. Network segmentation may reduce attack surface while remediation is planned.