Tech

Craft CMS zero-day exploited to compromise hundreds of vulnerable servers

Share
Share


  • Researchers discovered two critical-severity zero-days in Craft CMS
  • Criminals are allegedly chaining them together to gain access
  • Some 300 sites already fell victim

Cybercriminals are abusing two zero-day vulnerabilities in the Craft content management system (CMS) to access flawed servers and run malicious code remotely (RCE). This is according to cybersecurity researchers Orange Cyberdefense SenePost, who first saw the bugs being abused in mid-February this year.

The two vulnerabilities are now tracked as CVE-2025-32432, and CVE-2204-58136. The former is a remote code execution bug with the maximum severity score – 10/10 (critical).

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
New technique hides encryption keys under user data using standard 3D NAND flash memory
Tech

New technique hides encryption keys under user data using standard 3D NAND flash memory

Flash memory now doubles as secure key storage using conceal-and-reveal method Encryption...

Quordle hints and answers for Sunday, July 6 (game #1259)
Tech

Quordle hints and answers for Sunday, July 6 (game #1259)

Looking for a different day? A new Quordle puzzle appears at midnight...

NYT Connections hints and answers for Sunday, July 6 (game #756)
Tech

NYT Connections hints and answers for Sunday, July 6 (game #756)

Looking for a different day? A new NYT Connections puzzle appears at...

NYT Strands hints and answers for Sunday, July 6 (game #490)
Tech

NYT Strands hints and answers for Sunday, July 6 (game #490)

Looking for a different day? A new NYT Strands puzzle appears at...