CISA Alerts About Sitecore Remote Code Execution Vulnerabilities; Ongoing Attacks Impact Next.js and DrayTek Devices

The U.S.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has included two long-standing security vulnerabilities affecting Sitecore CMS and Experience Platform (XP) in its list of Known Exploited Vulnerabilities (KEV), following reports of active exploitation.
Below are the details of the identified vulnerabilities:

CVE-2019-9874 (CVSS score: 9.8) – An issue related to deserialization in the Sitecore.Security.AntiCSRF

About Author

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.