CISA Warns of Sitecore RCE Flaws; Active Exploits Hit Next.js and DrayTek Devices

Discussion in 'News Aggregator' started by The Hacker News, 27 Mar 2025.

  1. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two six-year-old security flaws impacting Sitecore CMS and Experience Platform (XP) to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities are listed below - CVE-2019-9874 (CVSS score: 9.8) - A deserialization vulnerability in the Sitecore.Security.AntiCSRF

    Continue reading...
     

Share This Page

Loading...