CVE-2025-27218

Medium severity, CVSS 5.3. EPSS: 65% chance of exploitation in the next 30 days.

Sitecore Experience Manager (XM) and Experience Platform (XP) 10.4 before KB1002844 allow remote code execution through insecure deserialization.

Published 2025-02-20. Last modified 2026-06-17.