logo

CISA Warns of Craft CMS Code Injection Vulnerability Exploited in Attacks

ID: db0f166e-2947-52fd-9e2b-8b9d8f1d11e1

STIX ID: report--db0f166e-2947-52fd-9e2b-8b9d8f1d11e1

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-03-23

Date Updated: 2026-05-05

Author: Abinaya

...
...

A critical code-injection vulnerability (CVE-2025-32432 / CWE-94) in Craft CMS allows unauthenticated remote code execution; CISA added it to the Known Exploited Vulnerabilities catalog (March 20, 2026) after confirming active exploitation. Organizations are urged to apply vendor patches or mitigations immediately, monitor for anomalous web access and unauthorized administrative activity, and follow CISA BOD 22-01 remediation guidance (federal deadline April 3, 2026).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.