Tech

Craft CMS zero-day exploited to compromise hundreds of vulnerable servers

Share
Share


  • Researchers discovered two critical-severity zero-days in Craft CMS
  • Criminals are allegedly chaining them together to gain access
  • Some 300 sites already fell victim

Cybercriminals are abusing two zero-day vulnerabilities in the Craft content management system (CMS) to access flawed servers and run malicious code remotely (RCE). This is according to cybersecurity researchers Orange Cyberdefense SenePost, who first saw the bugs being abused in mid-February this year.

The two vulnerabilities are now tracked as CVE-2025-32432, and CVE-2204-58136. The former is a remote code execution bug with the maximum severity score – 10/10 (critical).

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Email pioneer says SaaS needs to make sustainability part of its DNA
Tech

Email pioneer says SaaS needs to make sustainability part of its DNA

SaaS sector lags behind others in sustainability awareness and industry Digital emissions...

Jessica Jones is back – Krysten Ritter’s hard-hitting PI joins Daredevil: Born Again season two
Tech

Jessica Jones is back – Krysten Ritter’s hard-hitting PI joins Daredevil: Born Again season two

Jessica Jones is making a comeback in Daredevil: Born Again season two...

This new ChatGPT feature solves the most annoying thing about Deep Research
Tech

This new ChatGPT feature solves the most annoying thing about Deep Research

ChatGPT’s Deep Research feature can now export reports as PDFs The PDFs...