216.73.216.31

CVE-2025-53690

· Published 04/09/2025 02:00 · Modified 21/12/2025 16:57 · Author: Cybersecurity and Infrastructure Security Agency

Labels: CVE-2025-53690

Essential information

Published
04/09/2025 02:00
Modified
21/12/2025 16:57
Author
Cybersecurity and Infrastructure Security Agency
Creator
Cybersecurity and Infrastructure Security Agency
CVSS
9.0 CRITICAL (v3.1)
CISA KEV
Yes
CWE
CVSS vector
CVSS:3.1/AV:N/C:H/I:H/A:H

CVSS metrics

Description

Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud contain a deserialization of untrusted data vulnerability involving the use of default machine keys. This flaw allows attackers to exploit exposed ASP.NET machine keys to achieve remote code execution.

NVD status

NVD
View on NVD