CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2021-42237

KEV · ransomware Critical · CVSS 9.8

Sitecore Experience Platform (XP) — Insecure deserialization unauthenticated RCE

CVSS
9.8
nvd
EPSS
97.9%
100th pct
KEV
Listed
ransomware
Class
other
CWE-502, CWE-502

Description

Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required to exploit this vulnerability.

Search profile — drives PoC discovery

Symbols Report.ashxSitecore.Framework.Runtime.dllMachineKeyViewStateObjectStateFormatterdeserializationysoserialTypeConfuseDelegateActivitySurrogateSelector
Keywords CVE-2021-42237Sitecore XP deserialization RCESitecore 8.2 remote code executionSitecore insecure deserialization exploitSitecore XP unauthenticated RCE PoCSitecore Experience Platform RCESitecore deserialization ysoserial
Versions: Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7

Ranked PoCs (12) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T06:30:39.000Z