More

    Craft CMS zero-day exploited to compromise hundreds of vulnerable servers




    • Researchers discovered two critical-severity zero-days in Craft CMS
    • Criminals are allegedly chaining them together to gain access
    • Some 300 sites already fell victim

    Cybercriminals are abusing two zero-day vulnerabilities in the Craft content management system (CMS) to access flawed servers and run malicious code remotely (RCE). This is according to cybersecurity researchers Orange Cyberdefense SenePost, who first saw the bugs being abused in mid-February this year.

    The two vulnerabilities are now tracked as CVE-2025-32432, and CVE-2204-58136. The former is a remote code execution bug with the maximum severity score – 10/10 (critical).

    https://cdn.mos.cms.futurecdn.net/o6ATdVL2q4q82nwczDmEoS.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img