Craft CMS Zero-Dages utilized to compromise hundreds of vulnerable servers


  • Researchers discovered two critical-difficult zero days in craftsmms CMS
  • Criminals allegedly link them together to access
  • About 300 places already fell victim

Cyber ​​criminals abuse two zero-day vulnerabilities in Craft Content Management System (CMS) to access defective servers and run malicious code external (RCE). This is, according to cybersecurity scientists orange cyberdefense tendon post, which first saw bugs being abused in mid-February this year.

The two vulnerabilities are now traced as CVE-2025-32432 and CVE-2204-58136. The former is a remote code performance error with the maximum severity – 10/10 (critical).

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top