Attackers chained Craft CMS zero-days attacks in the wild
ID: 7cbff728-f99c-594f-988e-5030eb6a9595
STIX ID: report--7cbff728-f99c-594f-988e-5030eb6a9595
Feed Name: Security Affairs
Threat Score
Orange Cyberdefense’s CSIRT reported an in-the-wild campaign that chained two vulnerabilities—CVE-2025-32432 (Craft CMS RCE) and CVE-2024-58136 (Yii input validation)—to execute code via PHP session injection and install a PHP file manager on compromised servers; researchers identified ~13,000 vulnerable instances and ~300 potentially compromised sites, and published IoCs and patched versions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
