Find notable cyber news and cases, enriched with sources, timelines, and signals.

Sitecore actively exploited zero-day vulnerability (CVE-2025-53690)

Vulnerability
First reported
Last updated
Happening score
H score 34
3 unique sources, 5 articles

Summary

Hide ▲

CVE-2025-53690 is a critical Sitecore vulnerability under active exploitation for initial access. CISA advised FCEB agencies to update Sitecore by September 25, 2025 after the flaw was found in the wild, and Mandiant reported attackers abusing a publicly disclosed ASP.NET machine key to trigger remote code execution. The intrusion chain used WEEPSTEEL and tools including EarthWorm, DWAgent, and SharpHound to support reconnaissance, persistence, lateral movement, and data theft.

Related Happenings

Microsoft SharePoint Server actively exploited multi-CVE wave

Exploitation Wave
H score78 First: 15.07.2026 12:44 Last: 15.07.2026 12:44 Sources 1

About this happening: SharePoint Server exploitation wave remains active across internet-exposed on-premises instances, with CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 used...

CPanel & WHM authentication-bypass exploitation wave (CVE-2026-41940)

Exploitation Wave
H score89 First: 04.05.2026 11:25 Last: 04.05.2026 11:25 Sources 1

About this happening: Active exploitation of CVE-2026-41940 is driving a large cPanel & WHM compromise wave, putting exposed servers at risk of administrative takeover. More than 40,000 serve...

Storm-1175 high-velocity exploit campaign

Campaign
H score59 First: 06.04.2026 19:56 Last: 06.04.2026 19:56 Sources 1

About this happening: Storm-1175 is running a high-velocity exploit campaign that rapidly turns access into Medusa ransomware deployment, creating risk of data exfiltration and encrypte...

Langflow CVE-2026-33017 exploitation wave

Exploitation Wave
H score50 First: 20.03.2026 12:20 Last: 20.03.2026 12:20 Sources 1

About this happening: CVE-2026-33017 in Langflow was disclosed on March 17, 2026 as an unauthenticated RCE with CVSS 9.3, allowing arbitrary Python execution from a single HTTP requ...

Cloud environments third-party flaw exploitation wave

Exploitation Wave
H score37 First: 09.03.2026 23:45 Last: 09.03.2026 23:45 Sources 1

About this happening: Threat actors are rapidly weaponizing newly disclosed third-party vulnerabilities to reach cloud environments, compressing the exploitation window from weeks to days a...

Timeline

  1. 16.01.2026 09:18 6 articles · 6mo ago

    UAT-8837 exploitation of Sitecore CVE-2025-53690

    Initial Disclosure

    Researchers assess UAT-8837 as a likely China-nexus APT targeting North American critical infrastructure and using the Sitecore zero-day CVE-2025-53690 for initial access. After foothold, the actor is described as conducting reconnaissance, disabling RestrictedAdmin for RDP, opening cmd.exe, and deploying GoTokenTheft, EarthWorm, DWAgent, SharpHound, Impacket, GoExec, Rubeus, and Certipy for credential theft, tunneling, persistence, elevated command execution, and Active Directory discovery and abuse; in one victim organization it exfiltrated DLL-based shared libraries related to the victim's products.

    Show sources