CVE-2025-53690: Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability
Critical severity, CVSS 9.0. Actively exploited: in CISA KEV since 2025-09-04. EPSS: 52.5% chance of exploitation in the next 30 days.
Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (XM): through 9.0; Experience Platform (XP): through 9.0.
Affected products
- Sitecore Experience Commerce: up to and including 9.0
- Sitecore Experience Manager: up to and including 9.0
- Sitecore Experience Platform: up to and including 9.0
- Sitecore Managed Cloud: affected versions not specified
Published 2025-09-03. Last modified 2026-06-17.