CVE-2021-3129Active Exploitation(facade / ignition)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch facade ignition systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and file_put_contents(). This is exploitable on sites using debug mode with Laravel before 8.4.2.

8.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-10-09. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ignition
  • laravel

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 6 mentions across 5 observed days

What's happening

  • Active exploitation reported across 3 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Peaked 4d ago at 2 mentions (2026-03-01); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Products
ignitionlaravel

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-03-01: 2Mentions · 2026-07-18: 1Mentions · 2026-08-16: 1Mentions · 2026-09-01: 1Mentions · 2026-10-03: 1PoC Mentioned / Linked · 2026-07-18: 1PoC Mentioned / Linked · 2026-08-16: 1Exploit Tool / Code · 2026-08-16: 1Active Exploitation · 2026-03-01: 2Active Exploitation · 2026-09-01: 1Patch / Workaround · 2026-08-16: 1Technical Details · 2026-08-16: 1Technical Details · 2026-09-01: 103-0107-1808-1609-0110-03
Signal classification3 categories
Active Exploitation
360.0%
PoC
120.0%
Exploit
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-012
Active Exploitation2
2026-07-181
PoC1
2026-08-161
Exploit1
2026-09-011
Active Exploitation1
Full discourse6 posts
  • Dark Web Intelligence@DailyDarkWeb
    Active Exploitation

    🚨 CISA WARNS: TWO MORE VULNERABILITIES ARE BEING ACTIVELY EXPLOITED CISA has added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after confirming evidence of active exploitation. The newly added vulnerabilities are: * CVE-2021-3129 — Laravel Framework Ignition File Upload Vulnerability A vulnerability affecting Laravel applications using vulnerable versions of the Ignition error-page component. Under certain configurations, an unauthenticated remote attacker can abuse Ignition functionality to achieve remote code execution. * CVE-2026-24858 — Fortinet FortiOS/FortiProxy/FortiSwitchManager/FortiManager Authentication Bypass Vulnerability An authentication-bypass vulnerability affecting multiple Fortinet products that could allow an unauthenticated attacker with a FortiCloud account and registered device to log into other devices registered to different accounts. CISA added both vulnerabilities to KEV because they meet one of the most important criteria defenders should pay attention to: ⚠️ EVIDENCE OF ACTIVE EXPLOITATION. Federal Civilian Executive Branch agencies are required under BOD 22-01 to remediate KEV vulnerabilities by CISA's specified deadlines. But KEV should not be treated as a federal-government-only patch list. ⚠️ Analyst Note: The Laravel vulnerability is particularly interesting because CVE-2021-3129 is more than five years old. Its appearance in KEV again demonstrates an uncomfortable reality: Attackers don't necessarily need new zero-days. Internet-facing systems running old, exploitable software can remain valuable targets YEARS after a vulnerability becomes publicly known. The Fortinet vulnerability highlights a different problem: compromise of edge infrastructure. Firewalls, VPN gateways, management appliances and other perimeter devices sit at highly privileged positions in enterprise networks. When vulnerabilities in these systems become actively exploited, remediation should be treated as a priority rather than simply another item in the vulnerability-management queue. If either product exists in your environment, don't prioritize solely by CVSS. Prioritize by exploitation. Source: CISA — August 31, 2026 https://www.cisa.gov/news-events/alerts/2026/08/31/cisa-adds-two-known-exploited-vulnerabilities-catalog #DDW #CISA #KEV #Fortinet #CyberSecurity

    Post summary

    CISA reports that two CVEs, CVE-2021-3129 and CVE-2026-24858, are actively exploited, urging defenders to immediately remediate.

    0502716.8K
    206.6K followersView on X
  • Loginsoft Threat Intel@Loginsoft_Intel
    Active Exploitation

    Cytellite recent detection targeting CVE-2021-3129 — Tamatiya EOOD Visit -- https://cti.loginsoft.com/ip/79.124.58.198 #Loginsoft #Cytellite #Cybersecurity #CVE20213129 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/YVJELUc5nz

    Post summary

    Cytellite reports recent detection of activity exploiting CVE-2021-3129, indicating that the vulnerability is being actively exploited in the wild.

    00010165
    19 followersView on X
  • ♫Why♥Not♪@Python_s_

    NØØT Security Alerts Classification: Critical CVE: CVE-2021-3129 Product: Laravel / Ignition Summary: VulnCheck reports real-world exploitation activity affecting Laravel / Ignition. Evidence: Public PoC/exploit available; Ransomware use confirmed; Active exploitation reported; Severe impact class Impact: The vulnerability is associated with ransomware activity and may contribute to compromise of exposed systems. Action: Prioritize vendor remediation, identify exposed affected systems, and investigate for evidence of exploitation when applicable. 18 Mar 2021 Source: https://vulncheck.com/xdb/8168517a0701 #NØØT #CyberSecurity #InfoSec #ThreatIntelligence #CyberThreats #CVE #CyberDefense #Laravel #Ignition #CVE_2021_3129 #ActiveExploitation #Exploit #Ransomware #RansomwareAttack

    0000090
    226 followersView on X
  • Vulnerability Research Labs@vulnresearchlab
    Exploit

    A tool for finding errors in your code becomes the error. We reproduced the public code injection CVE-2021-3129 in Laravel Ignition's debug functionality. Exploit built, patch verified to close.

    Post summary

    Researchers reproduced the code injection CVE-2021-3129 in Laravel Ignition, built an exploit, and confirmed that patching closes the vulnerability.

    0000041
    7 followersView on X
  • the_naresh_offcial@the_Naresh_tech
    PoC

    I just published Exploiting CVE-2021–3129: A Hands-On Laravel Vulnerability Lab https://medium.com/p/exploiting-cve-2021-3129-a-hands-on-laravel-vulnerability-lab-606563290996?source=social.tw https://t.co/Ffb1TKDcEm

    Post summary

    The tweet promotes a Medium article that offers a hands‑on lab demonstrating exploitation of CVE‑2021‑3129, underscoring the existence of a working PoC.

    0000029
    6 followersView on X
  • Loginsoft Threat Intel@Loginsoft_Intel
    Active Exploitation

    Cytellite recent detection targeting CVE-2021-3129 — Tamatiya EOOD Visit -- https://cti.loginsoft.com/ip/79.124.58.198 #Loginsoft #Cytellite #Cybersecurity #CVE20213129 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/8olzN03ncg

    Post summary

    Cytellite reports recent detection of activity targeting CVE-2021-3129, indicating potential active exploitation, but no PoC, exploit code, patch, or technical details are provided.

    00000266
    19 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appfacadeignition-laravel-
Applaravellaravel---

Explore more