CVE-2025-53691 Details
Description
Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Remote Code Execution (RCE).This issue affects Experience Manager (XM): from 9.0 through 9.3, from 10.0 through 10.4; Experience Platform (XP): from 9.0 through 9.3, from 10.0 through 10.4.
A remote code execution vulnerability has been identified in Sitecore Experience Manager (XM) versions 9.0 through 9.3 and 10.0 through 10.4, as well as in Sitecore Experience Platform (XP) versions 9.0 through 9.3 and 10.0 through 10.4. This vulnerability arises from the deserialization of untrusted data, allowing for arbitrary code execution on the server.
Sitecore has released patches for this vulnerability. Instructions for applying the patch can be found in the Sitecore Support Knowledge Base articles KB1003667 and KB1003734.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 3, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://labs.watchtowr.com/cache-me-if-you-can-sitecore-experience-platform-cache-poisoning-to-rce/ | Wiz | ExploitThird Party Advisory |
| https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1003667 | Wiz | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-502 | Deserialization of Untrusted Data | Wiz |
Affected Products
| Product | Versions |
|---|---|
| sitecore experience commerce | >= 9.0, <= 10.4 |
CPE
Remediation
| |
| sitecore experience manager | >= 9.0, <= 10.4 |
CPE
Remediation
| |
| sitecore experience platform | >= 9.0, < 10.4 10.4 - |
CPE
Remediation
| |
| sitecore managed cloud | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Wiz |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 8, 2025 | Initial Analysis | [email protected] |
| Sep 3, 2025 | New CVE Received | Wiz |