CVE-2025-32432Active Exploitation(craftcms / craft_cms)

CRITICALCVSS 10.0 · CRITICALCISA KEV

Exploitation observed; activity peaked at 7 mentions and remains active

Immediate actions

  • Patch craftcms craft_cms systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to remote code execution. This is a high-impact, low-complexity attack vector. This issue has been patched in versions 3.9.15, 4.14.15, and 5.6.17, and is an additional fix for CVE-2023-41892.

8.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-04-03. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-94

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • craft_cms

Threat summary

  • Active exploitation appears in 16 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 32 mentions across 16 observed days

What's happening

  • Active exploitation reported across 16 signals
  • Exploit tool or code specified in 9 signals
  • PoC mentioned or linked in 9 signals
  • Patch or workaround mentioned in 15 signals
  • Technical details provided in 22 signals
  • Disclosure: 4 classified signals
  • Peaked 12d ago at 7 mentions (2026-03-23); latest day: 2
  • 32 total mentions across 16 days

Affected systems

Vendors
Products
craft_cms

Deep dive

Activity timeline32 mentions / 16d
02457Mentions · 2026-03-20: 4Mentions · 2026-03-21: 2Mentions · 2026-03-22: 3Mentions · 2026-03-23: 7Mentions · 2026-03-24: 2Mentions · 2026-03-27: 1Mentions · 2026-03-31: 1Mentions · 2026-05-16: 1Mentions · 2026-07-08: 1Mentions · 2026-07-10: 1Mentions · 2026-07-12: 1Mentions · 2026-07-14: 1Mentions · 2026-07-22: 2Mentions · 2026-07-23: 1Mentions · 2026-08-07: 2Mentions · 2026-09-18: 2PoC Mentioned / Linked · 2026-03-23: 1PoC Mentioned / Linked · 2026-07-08: 1PoC Mentioned / Linked · 2026-07-10: 1PoC Mentioned / Linked · 2026-07-14: 1PoC Mentioned / Linked · 2026-07-22: 2PoC Mentioned / Linked · 2026-07-23: 1PoC Mentioned / Linked · 2026-08-07: 1PoC Mentioned / Linked · 2026-09-18: 1Exploit Tool / Code · 2026-03-22: 1Exploit Tool / Code · 2026-03-23: 2Exploit Tool / Code · 2026-07-14: 1Exploit Tool / Code · 2026-07-22: 2Exploit Tool / Code · 2026-07-23: 1Exploit Tool / Code · 2026-08-07: 1Exploit Tool / Code · 2026-09-18: 1Active Exploitation · 2026-03-20: 2Active Exploitation · 2026-03-21: 1Active Exploitation · 2026-03-22: 3Active Exploitation · 2026-03-23: 6Active Exploitation · 2026-03-24: 1Active Exploitation · 2026-03-27: 1Active Exploitation · 2026-07-12: 1Active Exploitation · 2026-07-14: 1Patch / Workaround · 2026-03-20: 2Patch / Workaround · 2026-03-21: 1Patch / Workaround · 2026-03-22: 2Patch / Workaround · 2026-03-23: 5Patch / Workaround · 2026-03-24: 2Patch / Workaround · 2026-03-27: 1Patch / Workaround · 2026-07-22: 2Technical Details · 2026-03-20: 3Technical Details · 2026-03-21: 1Technical Details · 2026-03-22: 2Technical Details · 2026-03-23: 7Technical Details · 2026-03-24: 1Technical Details · 2026-03-27: 1Technical Details · 2026-03-31: 1Technical Details · 2026-07-08: 1Technical Details · 2026-07-10: 1Technical Details · 2026-07-14: 1Technical Details · 2026-07-22: 2Technical Details · 2026-08-07: 103-2003-2103-2203-2303-2403-2703-3105-1607-0807-1007-1207-1407-2207-2308-0709-18
Signal classification6 categories
Active Exploitation
1650.0%
PoC
618.8%
Disclosure
412.5%
General
39.4%
Patch
26.3%
Exploit
13.1%
Referenced assets34 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-204
Active Exploitation2Disclosure1General1
2026-03-212
Active Exploitation1Disclosure1
2026-03-223
Active Exploitation3
2026-03-237
Active Exploitation6Patch1
2026-03-242
Active Exploitation1Patch1
2026-03-271
Active Exploitation1
2026-03-311
Disclosure1
2026-05-161
General1
2026-07-081
PoC1
2026-07-101
PoC1
2026-07-121
Active Exploitation1
2026-07-141
Active Exploitation1
2026-07-222
PoC2
2026-07-231
PoC1
2026-08-072
Disclosure1PoC1
2026-09-182
Exploit1General1
Full discourse20 posts
  • NullSecurityX@NullSecurityX
    PoC

    New video is live! 🚀 CraftCMS RCE to Root via Telnetd Auth Bypass In this walkthrough, we exploit CraftCMS CVE-2025-32432 for RCE, discover MySQL credentials, abuse password reuse for SSH access, and escalate to root via Telnetd CVE-2026-24061. https://youtu.be/eS7OLz_2FQo

    Post summary

    The post shares a video walkthrough that demonstrates exploiting CraftCMS CVE-2025‑32432 to achieve RCE, leverage MySQL credentials, and ultimately bypass Telnetd authentication (CVE‑2026‑24061) to gain root access.

    0512695.1K
    12.3K followersView on X
  • NullSecurityX@NullSecurityX
    PoC

    CraftCMS RCE to Root via Telnetd Auth Bypass We exploit CraftCMS CVE-2025-32432 for RCE, discover MySQL credentials, abuse password reuse for SSH access, and escalate to root via Telnetd CVE-2026-24061. https://youtu.be/eS7OLz_2FQo

    Post summary

    The post demonstrates exploitation of CraftCMS RCE (CVE-2025-32432), credential discovery, SSH access via password reuse, and escalation to root through Telnetd CVE-2026-24061, accompanied by a YouTube video link.

    0101432.2K
    12.3K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(3/20追加) 🛡️No.1548 CVE-2025-31277 Apple Multiple Products Buffer Overflow Vulnerability ==================================== ✅概要 ・深刻度:重要⚠️ 8.8 (CVSS Base) / CISA-ADP ・種別:バッファ境界の不適切な制限 (CWE-119) ・CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Apple の複数製品において、悪意ある Web コンテンツの処理によりメモリ破損が発生し得る脆弱性。 ✅ChatGPTによる脆弱性評価 ・国内影響度判定:高 ・悪用難易度:中 ✅攻撃前提条件 ・被害者が細工された Web コンテンツを処理すること ・脆弱な Apple 製品を利用していること ✅悪用時影響 ・メモリ破損 ・任意コード実行の可能性 ・端末侵害の初期侵入点化 ✅悪用事例等に関する公開情報 ・PoC/Exploit:確認できず ・ITW:あり(Google Threat Intelligence Group が DarkSword での利用を報告。) ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-31277 https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/ https://support.apple.com/en-us/124147 🛡️No.1549 CVE-2025-43510 Apple Multiple Products Improper Locking Vulnerability ==================================== ✅概要 ・深刻度:重要⚠️ 7.8 (CVSS Base) / NVD ・種別:不適切なロック (CWE-667) ・CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 事前認証されていない攻撃者により、悪意あるアプリを介して、プロセス間で共有されるメモリに予期しない変更を生じさせる恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅攻撃前提条件 ・被害端末上で悪意あるアプリを実行させること ・脆弱な Apple 製品を利用していること ✅悪用時影響 ・共有メモリの不正変更 ・プロセス間干渉 ・後続の権限奪取やチェーン攻撃の踏み台化 ✅悪用事例等に関する公開情報 ・PoC/Exploit:確認できず ・ITW:あり(Google Threat Intelligence Group が、DarkSword の GPU サンドボックス脱出段階で使用したと説明。) ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-43510 https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/ https://support.apple.com/en-us/125632 🛡️No.1550 CVE-2025-43520 Apple Multiple Products Classic Buffer Overflow Vulnerability ==================================== ✅概要 ・深刻度:重要⚠️ 7.1 (CVSS Base) / NVD ・種別:境界外書き込み (CWE-787) / NVD、クラシックバッファオーバーフロー (CWE-120) / CISA-ADP ・CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H 事前認証されていない攻撃者により、悪意あるアプリを介して、予期しないシステム終了やカーネルメモリ書き込みを引き起こされる恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅攻撃前提条件 ・被害端末上で悪意あるアプリを実行させること ・脆弱な Apple 製品を利用していること ✅悪用時影響 ・システム異常終了 ・カーネルメモリ書き込み ・権限昇格や端末掌握の足掛かり ([NVD][6]) ✅悪用事例等に関する公開情報 ・PoC/Exploit:確認できず ・ITW:あり(GTIG が DarkSword の最終段階 `pe_main.js` において、脆弱性を悪用し物理/仮想メモリ でread/write primitive を構築すると説明) ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-43520 https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/ https://support.apple.com/en-us/125633 🛡️No.1551 CVE-2025-32432 Craft CMS Code Injection Vulnerability =================================== ✅概要 ・深刻度:緊急🔥 10.0 (CVSS Base) / NVD ・種別:コード生成の不適切な制御 (CWE-94) / GitHub, Inc. ・CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H 事前認証されていない攻撃者により、リモートからコード実行される恐れがあります。Craft CMS において、3.0.0-RC1 以上 3.9.15 未満、4.0.0-RC1 以上 4.14.15 未満、5.0.0-RC1 以上 5.6.17 未満が影響を受けます。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ✅攻撃前提条件 ・Craft CMS が外部公開されていること ・脆弱バージョンが稼働していること ・攻撃者は認証不要、ユーザー操作不要 ✅悪用時影響 ・未認証でのリモートコード実行 ・Web サーバ侵害 ・情報窃取 ・Web 改ざんや追加マルウェア設置 ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報あり ・ITW:あり(Craft CMS は 2025-04-17 に “exploited in the wild” を示唆する証拠を確認したと公表) ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-32432 https://github.com/craftcms/cms/security/advisories/GHSA-f3gw-9ww9-jmc3 https://craftcms.com/knowledge-base/craft-cms-cve-2025-32432](https://craftcms.com/knowledge-base/craft-cms-cve-2025-32432 🛡️No.1552 CVE-2025-54068 Laravel Livewire Code Injection Vulnerability ==================================== ✅概要 ・深刻度:緊急🔥 9.8 (CVSS Base) / NVD ・種別:コード生成の不適切な制御 (CWE-94) / GitHub, Inc. ・CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Livewire v3.0.0 以上 3.6.4 未満において、特定の component property update の hydration 処理に起因。事前認証されていない攻撃者により、特定条件下でリモートからコード実行される恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅攻撃前提条件 ・Livewire v3 系の脆弱バージョンが公開環境で稼働していること ・対象コンポーネントが特定の方法で mounted / configured されていること ✅悪用時影響 ・未認証でのリモートコマンド実行 ・アプリケーションサーバ侵害 ・情報窃取 ・追加マルウェア設置や横展開 ([NVD][7]) ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報あり ・ITW:あり(ThreatHunter .ai はイラン系脅威アクターから、CVE-2025-54068 向け custom Nuclei template と 9 confirmed targets を報告) ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-54068 https://github.com/livewire/livewire/security/advisories/GHSA-29cq-5w36-x7w3 https://www.threathunter.ai/blog/iranian-threat-actor-tools-techniques-iocs-ioas/ https://www.cisa.gov/news-events/alerts/2026/03/20/cisa-adds-five-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    The post catalogs five CVEs that are confirmed exploited by CISA, with public PoCs for two, detailed technical data, and available Apple patches.

    030414.0K
    42.8K followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: CVE-2025-32432 CVE-2025-57819 CVE-2026-48908 CVE-2026-76460 CVE-2026-85706 ..🧵👇

    Post summary

    The tweet lists several CVEs under a threat digest without providing details, PoC, exploits, patches, or confirmation of active exploitation.

    21030121
    47 followersView on X
  • Hermes Tool@Hermes_tooll
    Active Exploitation

    CISA adds actively exploited Apple, Craft CMS, and Laravel Livewire flaws to KEV catalog — including CVE-2025-32432 (RCE), CVE-2025-54068 (MuddyWater-linked), and multiple iOS bugs used by DarkSword exploit kit. Federal agencies must patch by April 3, 2026. #CISA #KEV #RCE #CyberSecurity https://securityaffairs.com/189776/security/u-s-cisa-adds-apple-laravel-livewire-and-craft-cms-flaws-to-its-known-exploited-vulnerabilities-catalog.html

    Post summary

    CISA identifies Apple, Craft CMS, and Laravel Livewire vulnerabilities as actively exploited, urges federal patches, and notes DarkSword kit usage and MuddyWater linkage.

    01022839
    3.0K followersView on X
  • ExploitGrid@exploitgrid
    Disclosure

    🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: EGE-GH-6VzYuGW ( CVE-2025-32432 ) EGE-GH-xiVZBJy ( CVE-2026-0092 ) EGE-GH-eHNcyov ( CVE-2024-21413 ) EGE-GH-9UtrTVp ( CVE-2024-21413 ) EGE-GH-Ix6VGxH ( CVE-2023-6553 ) ..🧵👇

    Post summary

    The tweet enumerates several CVE identifiers in a daily digest but provides no further technical, exploit, patch, or confidence details.

    20011173
    365 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    CVE-2025-32432 in Craft CMS enables unauthenticated RCE via PHP session poisoning; root privilege escalation follows via CVE-2026-24061, a telnetd auth bypass in GNU inetutils through 2.7, CISA KEV listed. - CVE-2025-32432 (actively exploited, CISA KEV added March 2026) hits Craft CMS 5.0-5.6.16 at the unauthenticated admin/actions/assets/generate-transform endpoint. The attack abuses CVE-2024-58136 in Yii Framework: sending __class alongside class lets Yii instantiate an attacker-controlled object (GuzzleHttp\Psr7\FnStream or yii\rbac\PhpManager) while Craft's own class check passes harmlessly. The attacker first poisons a PHP session file by embedding a PHP payload in the redirect URL logged when visiting admin/dashboard with a junk parameter, then triggers execution by pointing PhpManager's itemFile at /var/lib/php/sessions/sess_[id]. Metasploit module exploit/linux/http/craftcms_preauth_rce_cve_2025_32432 automates the full chain. - Post-exploitation pivots via the Craft .env file at /var/www/html/craft/.env, which stores plaintext DB credentials (CRAFT_DB_PASSWORD). Dumping the CraftCMS users table yields a bcrypt hash crackable with hashcat mode 3200 against rockyou.txt. - Root access comes from CVE-2026-24061 (CISA KEV added January 2026): GNU inetutils telnetd through 2.7 passes the USER env variable unsanitized to login(1). #DFIR_Radar

    Post summary

    The text reports that CVE‑2025‑32432 is actively exploited in the wild, with a contactar module automating the full RCE chain against Craft CMS and enabling privilege escalation via CVE‑2026‑24061.

    10011209
    1.8K followersView on X
  • CVERiskPilot@cveriskpilot
    Active Exploitation

    If you run Craft CMS, stop scrolling. CVE-2025-32432 is on the CISA KEV — remote code execution, no auth required, actively exploited in the wild. This is not a theoretical risk. Attackers are using it right now. Patch today, not next sprint. #AppSec #WebSecurity

    Post summary

    CVE-2025-32432 in Craft CMS is currently being exploited with remote code execution; an urgent patch is required.

    00030215
    13 followersView on X
  • Misbar | مسبار@MisbarSec
    Patch

    📌 تحديث لـ Roundcube Webmail: أصدرت Roundcube Webmail تحديثاً أمنياً، الإصدار 1.6.14، لمعالجة عدة ثغرات أمنية جسيمة تم تحديدها بالرموز CVE-2025-32432 وCVE-2023-5631. تُشكل هذه الثغرات خطراً كبيراً على بيانات المستخدمين وسلامة الخوادم، حيث تسمح باستغلالات محتملة تهدد استقرار النظام. يُنصح بشدة بتطبيق التحديث فوراً لتحييد هذه المخاطر وتحصين بيئات التشغيل ضد التهديدات المحتملة. 🔗 للمزيد: https://securityonline.info/roundcube-webmail-security-update-v1-6-14-arbitrary-file-write-patch/ #الامن_السيبراني #CyberSecurity #cve

    Post summary

    Roundcube Webmail issued patch 1.6.14 for CVE‑2025‑32432 and CVE‑2023‑5631, but the post does not mention exploit code, PoC, or active attacks.

    00030218
    81 followersView on X
  • Misbar | مسبار@MisbarSec
    Active Exploitation

    📌 تحذير CISA من استغلال ثغرة في Craft CMS أضافت CISA ثغرة حرجة (CVE-2025-32432) ضمن Craft CMS إلى قائمة الثغرات المعروفة والمستغلة فعلياً في الهجمات. تُصنف هذه الثغرة على أنها حقن تعليمات برمجية، وتُشكل خطراً جسيماً على الأنظمة المتأثرة. يستغل المهاجمون هذه الثغرة لتنفيذ تعليمات برمجية عن بُعد والتحكم بالأنظمة. يُنصح فرق الأمن ومديري الأنظمة بالتحقق الفوري من تطبيقات Craft CMS لديهم وتطبيق التحديثات والتدابير الوقائية اللازمة لمنع الاختراق. 🔗 للمزيد: https://cybersecuritynews.com/cms-code-injection-vulnerability-exploited/

    Post summary

    CISA highlights CVE-2025-32432 in Craft CMS as a remotely exploitable code injection vulnerability that is actively being used in attacks, urging users to apply patches and protective measures.

    00030541
    80 followersView on X
  • ThreatWire@ThreatWire_
    PoC

    🚨 A public PoC has been released for CVE-2025-32432 affecting Craft CMS. The vulnerability allows remote code execution (RCE) and has been patched in 3.9.15, 4.14.15, and 5.6.17. 🔗 https://github.com/c0gnit00/cve-2025-32432 #CraftCMS #RCE #CVE #CyberSecurity

    Post summary

    A public PoC for CVE-2025-32432, which allows RCE in Craft CMS, has been released with a GitHub link, and the vulnerability is patched in recent versions.

    00011126
    409 followersView on X
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2025-32432 PT ID: PT-2025-17927 Vendor: craftcms Product: cms Description: Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to remote code execution. This is a high-impact, low-complexity attack vector. This issue has been patched in versions 3.9.15, 4.14.15, and 5.6.17, and is an additional fix for CVE-2023-41892. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2025-17927 • https://github.com/c0gnit00/cve-2025-32432 #dbugs_vuln

    Post summary

    A PoC/exploit for CVE-2025-32432 has been discovered, with code available on GitHub, and the vulnerability has been patched in recent version releases of Craft CMS.

    00020517
    3.4K followersView on X
  • キタきつね@foxbook
    Active Exploitation

    CISAが既知の悪用された脆弱性5件をカタログに追加 CISA Adds Five Known Exploited Vulnerabilities to Catalog #CISA (Mar 20) CVE-2025-31277 Apple複数製品におけるバッファオーバーフローの脆弱性 CVE-2025-32432 Craft CMS コードインジェクションの脆弱性 CVE-2025-43510 Apple複数製品における不適切なロックの脆弱性 CVE-2025-43520 Apple複数製品におけるクラシックバッファオーバーフローの脆弱性 CVE-2025-54068 Laravel Livewireのコードインジェクション脆弱性 https://www.cisa.gov/news-events/alerts/2026/03/20/cisa-adds-five-known-exploited-vulnerabilities-catalog

    Post summary

    CISA announced the addition of five CVEs that are actively exploited to its catalog, confirming real‑world attacks but providing no patches, POCs, or exploit tools.

    00020256
    4.8K followersView on X
  • ExploitGrid@exploitgrid
    Exploit

    [EXPLOIT] CVE-2025-32432 [CRITICAL/PoC] CVE-2025-32432-exploit-by-P34NUT 🔗 https://exploitgrid.net/exploits/af54d33c-e698-45ec-a887-88b9590608e1

    Post summary

    The text announces a critical vulnerability (CVE-2025-32432) and directly shares a specific exploit via a dedicated link, making the primary focus an exploit disclosure.

    1000058
    47 followersView on X
  • ExploitGrid@exploitgrid
    PoC

    [EXPLOIT] EGE-GH-6VzYuGW [CRITICAL/PoC] Linked: CVE-2025-32432 craftcms-cve-2025-32432-rce 🔗 https://exploitgrid.net/exploits/4ff1cd89-06ca-4cfb-b5c8-6f47ca33d4cf

    Post summary

    A proof‑of‑concept and exploit code for CVE-2025-32432, an RCE in CraftCMS, have been published and linked.

    1000055
    29 followersView on X
  • z3n@zench4n
    General

    Traditional vulnerability research focuses on static flaws like CVE-2025-32432 in Craft CMS. In AI security, the flaw is often logic-based.

    Post summary

    The text merely references a CVE in Craft CMS without providing technical details, exploits, or remediation information.

    1000020
    1.4K followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    Active Exploitation

    CISAが既知の悪用された脆弱性5件をカタログに追加 https://www.cisa.gov/news-events/alerts/2026/03/20/cisa-adds-five-known-exploited-vulnerabilities-catalog CVE-2025-31277 Apple複数製品におけるバッファオーバーフローの脆弱性 CVE-2025-32432 Craft CMS コードインジェクションの脆弱性

    Post summary

    CISA has added five known exploited vulnerabilities to its catalog, including CVE‑2025‑31277 (Apple buffer overflow) and CVE‑2025‑32432 (Craft CMS code injection), indicating these weaknesses are actively exploited in the wild.

    10000148
    46 followersView on X
  • 0xPorosh 🇧🇩❤️🇵🇸@0Porosh
    PoC

    https://github.com/c0gnit00/cve-2025-32432

    Post summary

    The link points to a GitHub repository likely containing a proof‑of‑concept exploit for CVE‑2025‑32432, with no evidence of active exploitation, a patch, or false‑positive claims.

    0000047
    120 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers are exploiting CMS vulnerabilities (CVE-2025-32432, CVE-2026-0740) to deploy web shells and move laterally across networks. Runtime segmentation helps contain post-compromise activity when attackers pivot from compromised web servers. #CloudSecurity 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/australia-warns-of-global-campaign-targeting-vulnerable-cms-platforms-2026

    Post summary

    Analysis indicates that attackers are actively exploiting CVE‑2025‑32432 and CVE‑2026‑0740 to deploy web shells and facilitate lateral movement across networks, with runtime segmentation helping to contain post‑compromise activity.

    0000070
    1.9K followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2025-32432: Craft CMS Remote Code Execution Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q0492htx0

    Post summary

    The text announces a remote code execution vulnerability in Craft CMS (CVE‑2025‑32432) and hints at business impact and remediation steps, but it does not provide PoC, exploit, or patch details.

    00000217
    31 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcraftcmscraft_cms---

Explore more