CVE-2025-53690 is a critical zero-day vulnerability affecting Sitecore, a .NET-based Digital Experience Platform (DXP) widely used for enterprise websites, content management, and customer engagement.
The main Sitecore products affected include:
- Experience Manager (XM): content management and personalization.
- Experience Platform (XP): combines CMS with marketing automation and analytics.
- Experience Commerce (XC): e-commerce functionality integrated with content and marketing.
- Managed Cloud: Sitecore’s managed cloud service for enterprise customers.
| Product | Sitecore |
| Date | 2025-09-09 13:16:16 |
Technical Summary
CVE-2025-53690 is a ViewState deserialization vulnerability in Sitecore products, caused by the use of static and publicly known ASP.NET machine keys.
These keys were exposed in Sitecore deployment guides prior to 2017. ViewState is an ASP.NET mechanism that maintains the state of web forms between client and server. When machine keys are predictable or known, attackers can craft malicious ViewState payloads that, once deserialized, execute arbitrary code on the server.
Recommendations
- Immediately rotate ASP.NET machine keys: replace any sample or static machine keys in the web.config file with a new, randomly generated, and unique one.
- Add an encryption layer: encrypt any plaintext secrets within the
web.configfile. - Restrict access: limit access to the
web.configfile exclusively to application administrators.
Protect your organisation with Threat Intelligence and Digital Risk Protection.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
