Hackers exploited Sitecore zero-day flaw to deploy backdoors
Threat actors have been using WeepSteel reconnaissance malware by taking advantage of a zero-day vulnerability in older Sitecore implementations.
The inclusion of a sample ASP.NET machine key in pre-2017 Sitecore documentation led to the ViewState deserialization vulnerability, which is tracked under CVE-2025-53690.
By reusing this key in production, some customers made it possible for attackers who knew the key to create legitimate but malicious '_VIEWSTATE' payloads that deceived the server into deserializing and running them, resulting in remote code execution (RCE).
The problem is a misconfiguration vulnerability brought about by reusing publicly documented keys that were never intended for production, not an ASP.NET fault read more about Hackers exploited Sitecore zero-day f...



