Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Sitecore CMS and Experience Platform Deserialization Vulnerability in Anti-CSRF Module Allowing Remote Code Execution

Vulnerability

A deserialization vulnerability has been identified in the Sitecore.Security.AntiCSRF module, affecting Sitecore CMS versions 7.0 to 7.2 and Sitecore XP versions 7.5 to 8.2. This vulnerability allows an unauthenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter '__CSRFTOKEN'. The issue arises because the CSRF protection module expects a serialized object, which can be manipulated to create valid .NET objects that, when deserialized, lead to code execution on the server.

Impact

Exploitation of this vulnerability allows for remote code execution on the affected server.

Reproduction

The vulnerability can be reproduced by sending a POST request to a Sitecore application with a serialized .NET object in the '__CSRFTOKEN' parameter. This can be done using a tool like Burp Suite or Postman. The serialized object should be crafted to include a deserialization gadget that, when executed, will run arbitrary code on the server.

Remediation

Sitecore has released a patch for versions prior to 9.0. For Sitecore versions 9.0 and above, users should update to the latest version 9.1 Update-1.

Added: May 15, 2026, 9:57 AM
Updated: May 15, 2026, 9:57 AM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
7.5
exploitability
10.0
remediation
7.7
relevance
0.0
threat
9.8
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.