Sitecore XP RCE flaw is being actively exploited, ACSC warns
The vulnerability was fixed last month but hackers are now moving against patching laggards
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
You are now subscribed
Your newsletter sign-up was successful
The Australian Cyber Security Center (ACSC) has cautioned organizations that hackers are actively exploiting a remote code execution flaw in the Sitecore Experience Platform (Sitecore XP).
Successful exploitation of the vulnerability (CVE-2021-42237) results in remote code execution that “could allow an internet-based actor to install malware/ or webshells and perform other actions”, ACSC said in a statement.
“The ACSC is aware of active exploitation of this vulnerability in Australia,” it added.
Sitecore XP is a content management system (CMS) that combines customer data, analytics, artificial intelligence (AI), and marketing automation capabilities. This CMS is used heavily by enterprises, including many of the companies within the Fortune 500. The company rolled out a patch for the flaw in October.
“The vulnerability is related to a remote code execution vulnerability through insecure deserialization in the Report.ashx file," Sitecore said in a security advisory. "This file was used to drive the Executive Insight Dashboard (of Silverlight report) that was deprecated in 8.0 Initial Release."
The firm added that the vulnerability applies to all Sitecore systems running affected versions, including single-instance and multi-instance environments, Managed Cloud environments, and all Sitecore server roles (content delivery, content editing, reporting, processing, etc.), which are exposed to the internet.
According to Mitre’s CVE website on the flaw, Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is “vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required to exploit this vulnerability.”
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The flaw was first picked up by security researchers at Assetnote. Shubham Shah, co-founder, and CTO of Assetnote, said that while investigating the Sitecore product and its source code, his team found that the code does not require any authentication.
Shah added to remediate this vulnerability, admins can remove the Report.ashx file from /sitecore/shell/ClientBin/Reporting/. He said that in performing offensive security source code analysis his team often discovers there are critical vulnerabilities in enterprise software that are incredibly easy to exploit.
“The apps that we have been auditing are complex, however, the vulnerabilities are quite simple. With a concerted effort in taking apart these enterprise apps, we are able to discover critical vulnerabilities, after understanding the attack surface,” he said.
Sitecore has advised users to upgrade to version 9.0.0 or higher which protects against the vulnerability.
Rene Millman is a freelance writer and broadcaster who covers cybersecurity, AI, IoT, and the cloud. He also works as a contributing analyst at GigaOm and has previously worked as an analyst for Gartner covering the infrastructure market. He has made numerous television appearances to give his views and expertise on technology trends and companies that affect and shape our lives. You can follow Rene Millman on Twitter.
-
SMB cybersecurity in 2026: From reactive defense to strategic partnershipIndustry Insights Strategic partners help UK SMBs navigate cyber regulations and bridge leadership gaps
-
What’s the role of IT operations management in improving infrastructure visibility?ITOM can map out hardware and software dependencies, bringing order to chaotic IT infrastructure
-
Security agencies issue warning over critical Cisco Catalyst SD-WAN vulnerabilityNews Threat actors have been exploiting the vulnerability to achieve root access since 2023
-
Millions of developers could be impacted by flaws in Visual Studio Code extensions – here's what you need to know and how to protect yourselfNews The VS Code vulnerabilities highlight broader IDE security risks, said OX Security
-
CVEs are set to top 50,000 this year, marking a record high – here’s how CISOs and security teams can prepare for a looming onslaughtNews While the CVE figures might be daunting, they won't all be relevant to your organization
-
Microsoft patches six zero-days targeting Windows, Word, and more – here’s what you need to knowNews Patch Tuesday update targets large number of vulnerabilities already being used by attackers
-
Experts welcome EU-led alternative to MITRE's vulnerability tracking schemeNews The EU-led framework will reduce reliance on US-based MITRE vulnerability reporting database
-
Veeam patches Backup & Replication vulnerabilities, urges users to updateNews The vulnerabilities affect Veeam Backup & Replication 13.0.1.180 and all earlier version 13 builds – but not previous versions.
-
Two Fortinet vulnerabilities are being exploited in the wild – patch nowNews Arctic Wolf and Rapid7 said security teams should act immediately to mitigate the Fortinet vulnerabilities
-
Everything you need to know about Google and Apple’s emergency zero-day patchesNews A serious zero-day bug was spotted in Chrome systems that impacts Apple users too, forcing both companies to issue emergency patches
