logo

Sitecore CMS flaw let attackers brute-force 'b' for backdoor

ID: 2e56bd00-d660-5124-bb99-9793fefd4dd1

STIX ID: report--2e56bd00-d660-5124-bb99-9793fefd4dd1

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2025-06-17

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Security researchers at watchTowr disclosed three vulnerabilities in Sitecore Experience Platform — a hardcoded internal admin password, a ZIP path-traversal vulnerability, and an unrestricted file upload — that can be combined to achieve pre-authenticated remote code execution on unpatched instances; the team demonstrated exploitability and reported more than 22,000 exposed Sitecore instances, while Sitecore released patches in version 10.4 on May 11.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.