logo

Investigating an in-the-wild campaign using RCE in CraftCMS

ID: 22bf2720-c1a7-5b69-a9e7-3a33daf185db

STIX ID: report--22bf2720-c1a7-5b69-a9e7-3a33daf185db

Feed Name: SensePost Blog

Threat Score
75/100

Date Published: 2025-04-18

Date Updated: 2026-04-30

...
...

Orange Cyberdefense describes a confirmed, in-the-wild pre-auth RCE chain against Craft CMS (affecting 3.x–5.x) that abuses Yii behavior configuration to instantiate gadget classes and execute arbitrary PHP. The report covers forensic evidence of exploitation (logs and IOCs), technical root cause analysis, a lab reproduction and PoC exploit, detection templates, and a large-scale asset scan identifying thousands of vulnerable hosts and ~300 likely compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.