National Cyber Warfare Foundation (NCWF)

CISA Warns of Sitecore RCE Flaws; Active Exploits Hit Next.js and DrayTek Devices


0 user ratings
2025-03-27 06:51:53
milo
Blue Team (CND)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two six-year-old security flaws impacting Sitecore CMS and Experience Platform (XP) to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.
The vulnerabilities are listed below -

CVE-2019-9874 (CVSS score: 9.8) - A deserialization vulnerability in the Sitecore.Security.AntiCSRF



Source: TheHackerNews
Source Link: https://thehackernews.com/2025/03/cisa-flags-two-six-year-old-sitecore.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2025 - National Cyber Warfare Foundation - All rights reserved worldwide.