On March 6th, Searchlight Cyber published a blog revealing details about a new deserialization vulnerability in Sitecore &#;x26;#;x5b;1&#;x26;#;x5d;. Sitecore calls itself a “Digital Experience Platform (CXP),” which is a fancy content management system&#;x26;#;xc2;&#;x26;#;xa0;(CMS). Sitecore itself is written in .Net and is often sold as part of a solution offered by Sitecore partners. Like other CMSs, it makes it easy to manage a website&#;x26;#;39;s content. It offers several attractive features to marketing professionals seeking more insight into user patterns.
Continue reading Sitecore “thumbnailsaccesstoken” Deserialization Scans (and some new reports) CVE-2025-27218, (Thu, Mar 27th)→