VulnerAlert



CLOUD
GOOGLE
05-09-2025 13:16
Tags
#google
#site
#hacker
#exploit
#critical
#data
#order
#machine
#html
#form
#asp.net
#cloud
#vulnerability
#/.net(.*)core/iU
#.net core
#attackers
#threat
#security
#remote
#patch
#flaw
#execution
#discover
#critic
#allow
#attack
Descripción
CISA Orders Immediate Patch of Critical Sitecore Vulnerability Under Active Exploitation Federal Civilian Executive Branch (FCEB) agencies are being advised to update their instances by September 25, 2025, following the discovery a security flaw that has come under active exploitation in wild. The vulnerability , tracked as CVE-2025-53690 carries CVSS score 9.0 out maximum 10.0, indicating critical severity. "Sitecore Experience Manager (XM), Platform (XP), Commerce (XC), and Managed Cloud contain deserialization untrusted data involving use default machine keys," U.S. Cybersecurity Infrastructure Security Agency (CISA) said . "This allows attackers exploit exposed ASP.NET keys achieve remote code execution." Google-owned Mandiant, which discovered ViewState attack, activity leveraged sample key had been deployment guides from 2017 earlier. threat intelligence team ... https://thehackernews.com/2025/09/cisa-orders-immediate-patch-of-critical.html
CVE-2025-53690
Link externo
Ver detalles

Fuente
https://thehackernews.com/2025/09/cisa-orders-immediate-patch-of-critical.html
Resultados similares
Coincidentes en almenos en 50% de los tags
06-09-2025 CVE-2025-10046
The ELEX WooCommerce Google Shopping (Google Product Feed) plugin for WordPress is vulnerable t...
Ver información
05-09-2025 CVE-2025-58832
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabil...
Ver información
Icons made by Freepik from www.flaticon.com
Este Proyecto fue cofinanciado por el Consejo Nacional de Ciencia y Tecnología (CONACYT) a través del PROINNOVA 2021/2023
Proyecto realizado por