CVE-2025-53690: ViewState Deserialization Zero-Day Vulnerability Fixed in Sitecore Products
product_update Announcement β’ Rapid Migration and Modernization Program
highAction Required
product_update
Category
high
Priority
All Users
Target Audience
Yes
Action Required
Action Required
This announcement requires action from users. Please review the details below and take necessary steps.
Deadline: Past Due
Summary
Sitecore products have been patched to address a critical ViewState deserialization zero-day vulnerability (CVE-2025-53690). Users are urged to update immediately.
Details
Detailed information will be provided soon.
Next Steps
- Review the announcement details carefully
- Take required actions as outlined above
- Complete by
- Contact support if you have questions or need assistance
Source
Community Feedback
Community Score0
Help improve communications by rating the clarity and usefulness of this announcement