logo

MITRE Caldera Hit by Critical RCE Flaw (CVE-2025-27364) – Here’s What You Need to Know

ID: c1b2af76-9dd5-542d-863b-47bf7e18b40c

STIX ID: report--c1b2af76-9dd5-542d-863b-47bf7e18b40c

Feed Name: The Cyber Express

Threat Score
80/100

Date Published: 2025-02-28

Date Updated: 2026-04-23

Author: Ashish Khaitan

...
...

CVE-2025-27364 is a critical unauthenticated remote code execution flaw in MITRE Caldera (<=4.2.0) where attacker-controlled linker flags passed during dynamic agent compilation can cause arbitrary code execution on the Caldera server via gcc; MITRE rates this CVSS 10.0 and recommends upgrading to version 5.1.0+ and not exposing Caldera instances to the internet.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.