How to find Craft CMS on your network
ID: 351f8acf-8c4d-59da-8e46-19eb22e583f8
STIX ID: report--351f8acf-8c4d-59da-8e46-19eb22e583f8
Feed Name: runZero Blog
Threat Score
This advisory summarizes multiple serious vulnerabilities in Craft CMS — including a high-severity privilege escalation (CVE-2026-32267), critical zero-days being actively exploited via chained vulnerabilities (CVE-2025-32432 and CVE-2024-58136), and a code-injection RCE added to the KEV (CVE-2025-23209). It lists affected versions, provides available patched versions and mitigation steps (rotate security keys, hardening guidance), and offers detection queries for discovery.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
