PT-2025-35830 · Sitecore · Sitecore Experience Platform+1
Andi Slok
+4
·
Published
2025-09-02
·
Updated
2026-01-23
·
CVE-2025-53690
CVSS v3.1
9.0
Critical
| AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Sitecore Experience Manager (XM), Sitecore Experience Platform (XP), Experience Commerce (XC), and Managed Cloud versions through 9.0
Description
A deserialization of untrusted data issue exists in Sitecore products, allowing for code injection. This vulnerability, tracked as CVE-2025-53690, is actively exploited by the China-linked APT group UAT-8837, who have targeted North American critical infrastructure. The exploitation involves a ViewState deserialization flaw stemming from the use of a sample ASP.NET machine key included in documentation prior to 2017. Attackers are leveraging this to achieve remote code execution (RCE) and deploy malware, such as WeepSteel, Earthworm, and Dwagent. The vulnerability is present when using static machine keys and affects the /sitecore/blocked.aspx endpoint. Approximately 1.6 million services are estimated to be potentially affected. Exploitation involves crafting malicious ViewState payloads, enabling attackers to execute code and gain access to sensitive data.
Recommendations
Rotate all static machine keys in web.config with new unique keys.
Ensure the element within web.config is encrypted.
Implement regular rotation of static keys as a continuous security measure.
Exploit
Fix
RCE
LPE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sitecore Experience Manager
Sitecore Experience Platform