LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-10068: Kentico Xperience Deserialization of Untrusted Data Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 25, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 15, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-10068 to its Known Exploited Vulnerabilities catalog on Mar 25, 2022, with a federal patch deadline of Apr 15, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Kentico contains a failure to validate security headers. This deserialization can led to unauthenticated remote code execution.

CVE-2019-10068 is a deserialization of untrusted data vulnerability in Kentico Xperience. According to CISA, the product fails to validate security headers, and this deserialization can lead to unauthenticated remote code execution. For IT and security teams running Kentico Xperience, the issue matters because an unauthenticated attacker who can reach the affected functionality may execute code on the server, potentially compromising the application and underlying host.

Public detail is limited to the facts above; exact affected builds, attack prerequisites, and patch identifiers must be confirmed against the vendor advisory. Known ransomware use is not documented for this CVE.

How it works

The weakness is CWE-502 (Deserialization of Untrusted Data). In this class of flaw, an application accepts serialized objects or related data from an untrusted source and reconstructs them without adequate validation. When security headers or other integrity checks are not properly enforced, an attacker can supply crafted input that the deserializer treats as legitimate.

Abuse typically involves sending specially formed requests that trigger the deserialization path. Because the CISA summary describes the outcome as unauthenticated remote code execution, a successful exploit can run attacker-chosen code in the context of the Kentico process without prior login. Specific payload formats, endpoints, or gadget chains are not provided in the available facts and should not be assumed; defenders must rely on the vendor advisory for precise mechanics.

Am I affected? How to find it in your systems

Kentico Xperience is a content management and digital experience platform commonly deployed as web applications on Windows servers or in hosting environments that support .NET workloads. Inventory any servers, virtual machines, containers, or cloud instances that host Kentico sites, including development, staging, and production.

How to remediate

Patch first. Apply the updates provided by the vendor exactly as described in the Kentico advisory for CVE-2019-10068. CISA’s required action is to apply updates per vendor instructions.

If you can't patch immediately

Implement compensating controls to reduce risk until the vendor update can be applied.

If your data may have been exposed

Actively exploited vulnerabilities that yield remote code execution can lead to full system compromise and data theft. If you have evidence of exploitation or cannot rule it out, follow your incident-response process: isolate affected hosts, preserve logs and memory images, rotate credentials and secrets that the application could access, and assess what data the Kentico instance could reach. You can run a free exposure scan of your email addresses to check whether they appear in known breach data sets as one additional step in understanding potential impact.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedKentico · Xperience
WeaknessCWE-502
Added to CISA KEVMar 25, 2022
Federal patch deadlineApr 15, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities