logo

Attackers chained Craft CMS zero-days attacks in the wild

ID: 7cbff728-f99c-594f-988e-5030eb6a9595

STIX ID: report--7cbff728-f99c-594f-988e-5030eb6a9595

Feed Name: Security Affairs

Threat Score
72/100

Date Published: 2025-04-28

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Orange Cyberdefense’s CSIRT reported an in-the-wild campaign that chained two vulnerabilities—CVE-2025-32432 (Craft CMS RCE) and CVE-2024-58136 (Yii input validation)—to execute code via PHP session injection and install a PHP file manager on compromised servers; researchers identified ~13,000 vulnerable instances and ~300 potentially compromised sites, and published IoCs and patched versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.