This week’s update
This week, new critical vulnerabilities were disclosed in Sitecore’s Sitecore Experience Manager (XM), Sitecore Experience Platform (XP), specifically versions 9.0 through 9.3, and 10.0 through 10.4. These flaws are caused by unsafe data deserialization and code reflection, leaving affected systems at high risk of exploitation.
Key Findings
- CVE-2025-53690: Remote Code Execution through Insecure Deserialization
- CVE-2025-53691: Remote Code Execution through Insecure Deserialization
- CVE-2025-53693: HTML Cache Poisoning through Unsafe Reflections
Impact
Exploitation could allow attackers to execute arbitrary code remotely on the affected system and conduct cache poisoning attacks, potentially leading to further compromise. Applying the latest vendor-released solution without delay is strongly recommended.
| Ruleset | Rule ID | Legacy Rule ID | Description | Previous Action | New Action | Comments |
|---|---|---|---|---|---|---|
| Cloudflare Managed Ruleset | 588edc74df1f4609b3c2f7ef0ee2c15e | 100878 | Sitecore – Remote Code Execution – CVE:CVE-2025-53691 | N/A | Block | This is a new detection |
| Cloudflare Managed Ruleset | d1bd7563e6254db48ce703807c5b669c | 100631 | Sitecore – Cache Poisoning – CVE:CVE-2025-53693 | N/A | Block | This is a new detection |
| Cloudflare Managed Ruleset | ed94c7ce5301411a94a21a096c410240 | 100879 | Sitecore – Remote Code Execution – CVE:CVE-2025-53690 | N/A | Block | This is a new detection |
Source: Cloudflare
Latest Posts
- Microsoft 365 Copilot: Intelligent Summaries in Copilot Dashboard [MC1266912]
![Microsoft 365 Copilot: Intelligent Summaries in Copilot Dashboard [MC1266912] 2 pexels karolina grabowska 4199098](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Power Platform admin center – Environments page updates [MC1226444]
![Power Platform admin center – Environments page updates [MC1226444] 3 pexels 550498053 16792653](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Workflows, Workers – All Wrangler commands for Workflows now support local development

- Use Copilot to create and edit Pages in the Microsoft 365 Copilot mobile app [MC1266900]
![Use Copilot to create and edit Pages in the Microsoft 365 Copilot mobile app [MC1266900] 5 pexels pixabay 274192](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)

![Microsoft 365 Copilot: Intelligent Summaries in Copilot Dashboard [MC1266912] 2 pexels karolina grabowska 4199098](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-karolina-grabowska-4199098-150x150.webp)
![Power Platform admin center – Environments page updates [MC1226444] 3 pexels 550498053 16792653](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-550498053-16792653-150x150.webp)

![Use Copilot to create and edit Pages in the Microsoft 365 Copilot mobile app [MC1266900] 5 pexels pixabay 274192](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-pixabay-274192-150x150.webp)
