CVE-2025-53690: ViewState Deserialization Zero-Day Vulnerability Fixed in Sitecore Products

product_update Announcement β€’ Rapid Migration and Modernization Program

highAction Required
product_update
Category
high
Priority
All Users
Target Audience
Yes
Action Required

Action Required

This announcement requires action from users. Please review the details below and take necessary steps.

Deadline: Past Due

Summary

Sitecore products have been patched to address a critical ViewState deserialization zero-day vulnerability (CVE-2025-53690). Users are urged to update immediately.

Details

Detailed information will be provided soon.

Next Steps

  • Review the announcement details carefully
  • Take required actions as outlined above
  • Complete by
  • Contact support if you have questions or need assistance

Source

Google Cloud Blog | News, Features and Announcements
blog update
View original source β†’

Community Feedback

Community Score0

Help improve communications by rating the clarity and usefulness of this announcement