March 25, 2022 · Applied Cybernetics Group
CVE-2021-42237 — Sitecore XP
known ransomware use
Sitecore XP Remote Command Execution Vulnerability
- Added to KEV
2022-03-25- Federal due date
2022-04-15- Vendor
- Sitecore
- Product
- XP
- EPSS
- 99.9th percentile (score 0.979, as of
2026-07-13) - NVD CVSS v3.1
- 9.8 (CRITICAL)
- Ransomware use
- Known
- ATT&CK
- T1059 · signal rollup
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2021-42237
CISA short description
Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution.
Required action
Apply updates per vendor instructions.
NVD description
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required to exploit this vulnerability.