logo

How to find Craft CMS on your network

ID: 351f8acf-8c4d-59da-8e46-19eb22e583f8

STIX ID: report--351f8acf-8c4d-59da-8e46-19eb22e583f8

Feed Name: runZero Blog

Threat Score
88/100

Date Published: 2025-02-21

Date Updated: 2026-04-29

Author: runZero Team

...
...

This advisory summarizes multiple serious vulnerabilities in Craft CMS — including a high-severity privilege escalation (CVE-2026-32267), critical zero-days being actively exploited via chained vulnerabilities (CVE-2025-32432 and CVE-2024-58136), and a code-injection RCE added to the KEV (CVE-2025-23209). It lists affected versions, provides available patched versions and mitigation steps (rotate security keys, hardening guidance), and offers detection queries for discovery.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.