← Sitecore

2025 Sitecore Experience Platform — CVE-2025-53690 ViewState / machineKey RCE; active exploitation

2025 Unknown records affected Share on X

Data compromised

Tenant-dependent: CMS content, credentials, and adjacent directory data on compromised customer servers

Technical writeup

Independent research coordinated with Sitecore and Mandiant identified critical insecure deserialization (CVE-2025-53690, CVSS ~9.0) in ASP.NET ViewState handling when deployments reused public sample machineKey values from legacy documentation. Attack chains achieved remote code execution, credential theft, and deployment of malware such as the WeepSteel backdoor across customer Internet-facing Content Management instances. CISA added the flaw to its Known Exploited Vulnerabilities catalog; separately disclosed June 2025 chains (e.g., hardcoded service credentials in some versions) also received patches but represent overlapping hardening themes rather than a single root cause.

Root cause

Default/sample cryptographic keys enabling ViewState deserialization to RCE on customer-managed Sitecore hosts (CVE-2025-53690)

References