Tracking a SugarCRM Zero-Day
ID: f610b5ae-800a-5d5a-afcf-6ebe9f5b938e
STIX ID: report--f610b5ae-800a-5d5a-afcf-6ebe9f5b938e
Feed Name: Censys Blog
Date Published: 2023-01-05
Date Updated: 2026-04-27
Author: Brenda Mendoza; Mark Ellzey; Senior Security Researcher
Censys reports on CVE-2023-22952, an authentication bypass in SugarCRM actively exploited in the wild to upload a PNG-encoded PHP webshell that executes base64-decoded commands; Censys observed hundreds of compromised hosts (reporting ~354 unique compromised IPs from ~3,059 Internet-facing SugarCRM instances), provides IOCs and detection commands (e.g., strings $INSTALLDIR/cache/images/* | grep -i PHP), and recommends applying SugarCRM hotfixes/updates and monitoring /cache/images/ HTTP requests.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
