logo

ViewState Deserialization Zero-Day Vulnerability in Sitecore Products (CVE-2025-53690)

ID: 1b47582a-5caf-5cc9-8020-20c21aacba30

STIX ID: report--1b47582a-5caf-5cc9-8020-20c21aacba30

Feed Name: Threat Intelligence

Threat Score
70/100

Date Published: 2025-09-03

Date Updated: 2026-04-27

Author: Mandiant

...
...

Mandiant observed a threat actor exploiting a Sitecore Content Delivery instance via repeated HTTP POSTs to a blocked.aspx endpoint, achieving NETWORK SERVICE (w3wp.exe) privileges, archiving and exfiltrating the web root (including web.config), and performing host and network reconnaissance (processes, services, accounts, TCP/IP, active connections) to enable further post-exploitation activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.