Tech

Craft CMS zero-day exploited to compromise hundreds of vulnerable servers

Share
Share


  • Researchers discovered two critical-severity zero-days in Craft CMS
  • Criminals are allegedly chaining them together to gain access
  • Some 300 sites already fell victim

Cybercriminals are abusing two zero-day vulnerabilities in the Craft content management system (CMS) to access flawed servers and run malicious code remotely (RCE). This is according to cybersecurity researchers Orange Cyberdefense SenePost, who first saw the bugs being abused in mid-February this year.

The two vulnerabilities are now tracked as CVE-2025-32432, and CVE-2204-58136. The former is a remote code execution bug with the maximum severity score – 10/10 (critical).

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Simulator optimizes vehicle resources to enable real-time accident prevention in autonomous cars
Tech

Simulator optimizes vehicle resources to enable real-time accident prevention in autonomous cars

Traffic-Cognitive Integrated Network-Computing Load Distribution Simulator. Credit: Traffic-Cognitive Integrated Network-Computing Load Distribution...

Teaching robots to weld by using human expertise could solve UK’s critical welder shortage
Tech

Teaching robots to weld by using human expertise could solve UK’s critical welder shortage

Credit: CC0 Public Domain Robots could be the solution to filling the...

WhatsApp is officially getting ads – and I’m worried it’s a slippery slope from here
Tech

WhatsApp is officially getting ads – and I’m worried it’s a slippery slope from here

WhatsApp is finally getting ads They’ll appear in the Updates tab, integrated...