Tech

Craft CMS zero-day exploited to compromise hundreds of vulnerable servers

Share
Share


  • Researchers discovered two critical-severity zero-days in Craft CMS
  • Criminals are allegedly chaining them together to gain access
  • Some 300 sites already fell victim

Cybercriminals are abusing two zero-day vulnerabilities in the Craft content management system (CMS) to access flawed servers and run malicious code remotely (RCE). This is according to cybersecurity researchers Orange Cyberdefense SenePost, who first saw the bugs being abused in mid-February this year.

The two vulnerabilities are now tracked as CVE-2025-32432, and CVE-2204-58136. The former is a remote code execution bug with the maximum severity score – 10/10 (critical).

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Luxury brands’ use of NFTs as digital twins may undermine the perceived value of physical products, study finds
Tech

Luxury brands’ use of NFTs as digital twins may undermine the perceived value of physical products, study finds

Credit: Pixabay/CC0 Public Domain In an era where technology and luxury converge,...

What NFTs and ‘Antiques Roadshow’ have in common
Tech

What NFTs and ‘Antiques Roadshow’ have in common

Credit: Pixabay/CC0 Public Domain Anybody who’s ever watched “Antiques Roadshow” knows the...

Huawei unveils Ascend 920 in China one day after Trump bans Nvidia H20 AI chip exports
Tech

Huawei unveils Ascend 920 in China one day after Trump bans Nvidia H20 AI chip exports

US bans Nvidia’s H20 just as Huawei reveals its next-gen Ascend 920...

Engineers fortify wood with eco-friendly nano-iron
Tech

Engineers fortify wood with eco-friendly nano-iron

A microCT image that shows the distribution of the iron mineral in...