CISA has added two critical Sitecore CMS vulnerabilities (CVE-2019-9874 and CVE-2019-9875) to its Known Exploited Vulnerabilities catalog due to evidence of active exploitation. They allow remote code execution and affect multiple Sitecore versions. Organizations are urged to apply patches by April 2025 and implement temporary workarounds if they cannot upgrade immediately.

Microsoft Strengthens Outlook’s Email Ecosystem to Protect Inboxes
Microsoft Outlook will implement stricter authentication for domains sending over 5,000 emails daily starting May 5, 2025. Compliance with SPF, DKIM, and DMARC protocols is