logo

CISA orders federal agencies to patch Sitecore zero-day following hacking reports

ID: f225abfb-70d6-5cdd-8012-e50b80a45902

STIX ID: report--f225abfb-70d6-5cdd-8012-e50b80a45902

Feed Name: The Record from Recorded Future News

Threat Score
75/100

Date Published: 2025-09-05

Date Updated: 2026-05-01

...
...

Sitecore disclosed CVE-2025-53690 affecting multiple products where many deployments used an unchanged sample ASP.NET machine key; Mandiant reported stopping an attack that used the exposed key to compromise internet-facing Sitecore instances, deploy WEEPSTEEL reconnaissance malware, escalate privileges, and attempt to access sensitive files and create admin accounts. Sitecore now auto-generates unique machine keys for new deployments, customers were advised to rotate keys and search for suspicious activity, and CISA added the vulnerability to its known exploited vulnerabilities catalog with a September 25 patch deadline for federal civilian agencies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.