<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Sitecore</title><description>Actively exploited vulnerabilities affecting Sitecore products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/sitecore.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2025-53690 — Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-53690</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-53690</guid><description>Sitecore&apos;s XM, XP, XC, and Managed Cloud products ship with default ASP.NET machine keys that attackers can exploit to deserialize malicious data. Because machine keys are used to validate and decrypt data like view state and cookies, knowing these keys lets an unauthenticated attacker craft payloads the server will blindly process, resulting in remote code execution. Any internet-exposed Sitecore instance using default keys is effectively wide open to full server compromise.</description><pubDate>Thu, 04 Sep 2025 00:00:00 GMT</pubDate><category>Sitecore</category><category>Multiple Products</category></item></channel></rss>