Managed Cloud
11 CVEs tracked. 1 of them are in CISA KEV.
This hub aggregates every CVE we track for Managed Cloud, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.
Managed Cloud CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 3 |
| 2025-07 | 2 |
| 2025-08 | 0 |
| 2025-09 | 4 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 11 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical3
- High6
Latest CVEs
The 11 most recently published vulnerabilities affecting Managed Cloud.
- CVE-2025-53690Sitecore Products ViewState Deserialization Vulnerability9.0
- CVE-2025-53691Sitecore Experience Remote Code Execution through Insecure Deserialization8.8
- CVE-2025-53693HTML Cache Poisoning through Unsafe Reflections9.8
- CVE-2025-53694Information Disclosure in ItemServices API7.5
- CVE-2022-4979Sitecore XP 7.5 - 10.2, CMS 7.2, and Managed Cloud XSS—
- CVE-2025-34139Sitecore XM/XP/XC and Managed Cloud 8.0 - 10.4 Arbitrary File Read—
- CVE-2025-34511Sitecore PowerShell Extension RCE via Unrestricted Upload8.8
- CVE-2025-34510Sitecore XM, XC, and XP Post-Auth RCE via Zip Slip8.8
- CVE-2025-34509Sitecore XM and XP Hardcoded Credentials7.5
- CVE-2023-35813Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3.9.8
- CVE-2023-33651An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v9.0 Initial Release to v13.0 Initial Release allows attackers to by...7.5
Product grouping is registry-driven, with AI assist and human review. How it works