Tech

Craft CMS zero-day exploited to compromise hundreds of vulnerable servers

Share
Share


  • Researchers discovered two critical-severity zero-days in Craft CMS
  • Criminals are allegedly chaining them together to gain access
  • Some 300 sites already fell victim

Cybercriminals are abusing two zero-day vulnerabilities in the Craft content management system (CMS) to access flawed servers and run malicious code remotely (RCE). This is according to cybersecurity researchers Orange Cyberdefense SenePost, who first saw the bugs being abused in mid-February this year.

The two vulnerabilities are now tracked as CVE-2025-32432, and CVE-2204-58136. The former is a remote code execution bug with the maximum severity score – 10/10 (critical).

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
FBI places bounty on Salt Typhoon,  million for info on infamous Chinese hacking group
Tech

FBI places bounty on Salt Typhoon, $10 million for info on infamous Chinese hacking group

FBI is asking the public for help identifying Salt Typhoon It says...

These cool slim headphones mix ’80s looks with 2025 features, including noise cancellation
Tech

These cool slim headphones mix ’80s looks with 2025 features, including noise cancellation

KM5 Lightwear HP1 cost $189 / £159 (about AU$331) 1980s looks, but...

Microsoft previews a paid reboot reduction service for Windows Server 2025
Tech

Microsoft previews a paid reboot reduction service for Windows Server 2025

Hotpatch updates for Windows Server 2025 Standard and Datacenter will be chargeable...