Three new safety vulnerabilities have been disclosed within the Sitecore Expertise Platform that may very well be exploited to realize data disclosure and distant code execution.
The failings, per watchTowr Labs, are listed beneath –
CVE-2025-53693 – HTML cache poisoning by unsafe reflections
CVE-2025-53691 – Distant code execution (RCE) by insecure deserialization
CVE-2025-53694 –