CVE-2021-42237
KEV · ransomware Critical · CVSS 9.8Sitecore Experience Platform (XP) — Insecure deserialization unauthenticated RCE
- CVSS
- 9.8
- nvd
- EPSS
- 97.9%
- 100th pct
- KEV
- Listed
- ransomware
- Class
- other
- CWE-502, CWE-502
Description
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required to exploit this vulnerability.
Search profile — drives PoC discovery
Symbols Report.ashxSitecore.Framework.Runtime.dllMachineKeyViewStateObjectStateFormatterdeserializationysoserialTypeConfuseDelegateActivitySurrogateSelector
Keywords CVE-2021-42237Sitecore XP deserialization RCESitecore 8.2 remote code executionSitecore insecure deserialization exploitSitecore XP unauthenticated RCE PoCSitecore Experience Platform RCESitecore deserialization ysoserial
Versions: Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7
Ranked PoCs (12) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 14
- ★ 1vesperp/CVE-2021-42237-SiteCore-XP needs reviewgh_search · Python
- ★ 034zY/APT-Backpack needs reviewtrickest
- ★ 0PinkDev1/CVE-2021-42237 needs reviewtrickest
- ★ 0SYRTI/POC_to_review needs reviewtrickest
- ★ 0SohelParashar/.Net-Deserialization-Cheat-Sheet needs reviewtrickest
- ★ 0WhooAmii/POC_to_review needs reviewtrickest
- ★ 0aalexpereira/pipelines-tricks needs reviewtrickest
- ★ 0crankyyash/SiteCore-RCE-Detection needs reviewgh_search · Python
- ★ 0f0ur0four/Insecure-Deserialization needs reviewtrickest
- ★ 0soosmile/POC needs reviewtrickest
- ★ 0trhacknon/Pocingit needs reviewtrickest
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
- http://packetstormsecurity.com/files/164988/Sitecore-Experience-Platform-XP-Remote-Code-Execution.html
- https://blog.assetnote.io/2021/11/02/sitecore-rce/
- https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1000776
- http://packetstormsecurity.com/files/164988/Sitecore-Experience-Platform-XP-Remote-Code-Execution.html
- https://blog.assetnote.io/2021/11/02/sitecore-rce/
- https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1000776
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-42237
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T06:30:39.000Z