ViewState Deserialization Zero-Day Vulnerability in Sitecore Products (CVE-2025-53690)
ID: 1b47582a-5caf-5cc9-8020-20c21aacba30
STIX ID: report--1b47582a-5caf-5cc9-8020-20c21aacba30
Feed Name: Threat Intelligence
Threat Score
Mandiant observed a threat actor exploiting a Sitecore Content Delivery instance via repeated HTTP POSTs to a blocked.aspx endpoint, achieving NETWORK SERVICE (w3wp.exe) privileges, archiving and exfiltrating the web root (including web.config), and performing host and network reconnaissance (processes, services, accounts, TCP/IP, active connections) to enable further post-exploitation activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
