logo

Craft CMS RCE exploit chain used in zero-day attacks to steal data

ID: 1da18b93-1ed9-5353-89dd-7674435cc682

STIX ID: report--1da18b93-1ed9-5353-89dd-7674435cc682

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2025-04-25

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Two zero-day vulnerabilities in Craft CMS were chained in active attacks: CVE-2025-32432 (an RCE in Craft CMS) was used to store a malicious "return URL" in a PHP session file, and CVE-2024-58136 (an input validation flaw in the Yii framework) allowed execution of PHP code from that session to install a PHP-based file manager. Orange Cyberdefense observed subsequent uploads of backdoors and data exfiltration; patches for Yii and Craft CMS were released and SensePost published IoCs and a full investigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.