← Blog

Sitecore: APT Zero-Day CVE-2025-53690 Hits Critical Infra

Share on X

January 2026 summaries from specialist outlets described a China-linked APT cluster (reporting referenced designations such as UAT-8837) using the already-disclosed Sitecore CVE-2025-53690 ViewState / machineKey weakness as an initial-access path in critical infrastructure intrusions. The narratives built on late-2025 coordinated disclosure, CISA KEV listing, and enterprise forensic work around WeepSteel-class post-exploitation.

Canonical product-exploitation record: Sitecore CVE-2025-53690 exploitation wave on BreachHistory.

Source: The Hacker News