Description
Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (XM): through 9.0; Experience Platform (XP): through 9.0.
CISA Known Exploited Vulnerability
Date added 2025-09-04 | Due date 2025-09-25
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Problem types
CWE-502 Deserialization of Untrusted Data
Product status
Any version
Any version
Credits
Mandiant Threat Defense
References
cloud.google.com/...e-deserialization-zero-day-vulnerability
support.sitecore.com/...ticle_view&sysparm_article=KB1003865