RULE(RULE ID:338832)

Rule General Information
Release Date: 2025-04-29
Rule Name: Sitecore Experience Manager And Experience Platform Remote Code Execution Vulnerability (CVE-2025-27218)
Severity:
CVE ID:
Rule Protection Details
Description: Sitecore Experience Manager (XM) and Experience Platform (XP) 10.4 before KB1002844 allow remote code execution through insecure deserialization.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1003535
Solutions
Please refer to announcements or patches release by the vendor: https://support.sitecore.com/kb