Please note Office visits are by appointment only. We support businesses with 10+ users or workstations, or with servers or cloud services to manage. No residential or walk-in computer repair. Book a time →

Researchers Warn of Sitecore Exploit Chain Linking Cache Poisoning and Remote Code Execution

Three new security vulnerabilities have been disclosed in the Sitecore Experience Platform that could be exploited to achieve information disclosure and remote code execution. 
The flaws, per watchTowr Labs, are listed below –

CVE-2025-53693 – HTML cache poisoning through unsafe reflections
CVE-2025-53691 – Remote code execution (RCE) through insecure deserialization
CVE-2025-53694 –