{"id":"CVE-2021-42237","title":"Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine","summary":"Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is requir…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-502","CWE-502"],"vendor":"sitecore","product":"experience_platform","affected":["experience_platform = 7.5","experience_platform = 8.0","experience_platform = 8.1","experience_platform = 8.2"],"published":"2021-11-05","updated":"2026-07-05","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-42237","references":[{"url":"http://packetstormsecurity.com/files/164988/Sitecore-Experience-Platform-XP-Remote-Code-Execution.html","label":"cve@mitre.org"},{"url":"https://blog.assetnote.io/2021/11/02/sitecore-rce/","label":"cve@mitre.org"},{"url":"https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1000776","label":"cve@mitre.org"},{"url":"http://packetstormsecurity.com/files/164988/Sitecore-Experience-Platform-XP-Remote-Code-Execution.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://sitecore.com","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://blog.assetnote.io/2021/11/02/sitecore-rce/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1000776","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-42237","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available"],"epss":0.97904,"epssPercentile":0.99906,"kev":true,"kevDateAdded":"2022-03-25","kevDueDate":"2022-04-15","kevRansomware":true,"exploited":true,"zeroDay":true,"ingestedAt":"2026-07-06T01:08:17.057Z","exploits":{"github":3,"githubRepos":["https://github.com/ItsIgnacioPortal/CVE-2021-42237","https://github.com/vesperp/CVE-2021-42237-SiteCore-XP","https://github.com/crankyyash/SiteCore-RCE-Detection"],"metasploit":["exploit/windows/http/sitecore_xp_cve_2021_42237"],"nuclei":["CVE-2021-42237"],"checkedAt":"2026-09-21T15:24:32.987Z"},"exploitAvailable":true,"slug":"CVE-2021-42237","body":"## Overview\n\nSitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required to exploit this vulnerability.\n\n## Affected\n\n- `experience_platform = 7.5`\n- `experience_platform = 8.0`\n- `experience_platform = 8.1`\n- `experience_platform = 8.2`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"hadal","depthScore":100,"depthScoreParts":{"impact":53.9,"likelihood":19.6,"exploitation":25,"ransomware":5},"changes":[{"seq":4546,"id":"CVE-2021-42237","ts":1788887189708,"field":"exploit_available","old":"false","new":"true"},{"seq":3429,"id":"CVE-2021-42237","ts":1788886306954,"field":"exploit_available","old":"true","new":"false"},{"seq":2284,"id":"CVE-2021-42237","ts":1788882976670,"field":"exploit_available","old":"false","new":"true"},{"seq":1313,"id":"CVE-2021-42237","ts":1788882388633,"field":"exploit_available","old":"true","new":"false"},{"seq":427,"id":"CVE-2021-42237","ts":1788881824218,"field":"exploit_available","old":"false","new":"true"}]}