Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Sitecore CMS and Experience Platform Deserialization Vulnerability in Anti-CSRF Module Allowing Remote Code Execution

Vulnerability

A deserialization vulnerability has been identified in the anti-CSRF module of Sitecore CMS and Experience Platform (XP) versions through 9.1. This vulnerability allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in an HTTP POST parameter. In Sitecore versions 8.x, this vulnerability can be exploited without authentication, while in versions 9.x prior to 9.1.1, authentication is required.

Impact

Exploitation of this vulnerability allows for arbitrary code execution on the server.

Reproduction

The vulnerability can be reproduced by sending a POST request to a Sitecore application with a serialized .NET object in the __CSRFTOKEN parameter. The anti-CSRF module will deserialize the object, leading to remote code execution.

Remediation

Sitecore has released a patch for versions prior to 9.0. For versions 9.0 and above, users should update to the latest version 9.1 Update-1.

Added: May 15, 2026, 1:51 PM
Updated: May 15, 2026, 1:51 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
7.5
exploitability
6.5
remediation
7.7
relevance
0.0
threat
8.3
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.