piyokango[verified]@piyokangoActive Exploitation
The post catalogs five CVEs that are confirmed exploited by CISA, with public PoCs for two, detailed technical data, and available Apple patches.
Hermes Tool[verified]@Hermes_toollActive Exploitation
CISA identifies Apple, Craft CMS, and Laravel Livewire vulnerabilities as actively exploited, urges federal patches, and notes DarkSword kit usage and MuddyWater linkage.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
The text reports that CVE‑2025‑32432 is actively exploited in the wild, with a contactar module automating the full RCE chain against Craft CMS and enabling privilege escalation via CVE‑2026‑24061.
CVERiskPilot[verified]@cveriskpilotActive Exploitation
CVE-2025-32432 in Craft CMS is currently being exploited with remote code execution; an urgent patch is required.
Misbar | مسبار[verified]@MisbarSecPatch
Roundcube Webmail issued patch 1.6.14 for CVE‑2025‑32432 and CVE‑2023‑5631, but the post does not mention exploit code, PoC, or active attacks.
Misbar | مسبار[verified]@MisbarSecActive Exploitation
CISA highlights CVE-2025-32432 in Craft CMS as a remotely exploitable code injection vulnerability that is actively being used in attacks, urging users to apply patches and protective measures.
dbugs[verified]@ptdbugsPoC
A PoC/exploit for CVE-2025-32432 has been discovered, with code available on GitHub, and the vulnerability has been patched in recent version releases of Craft CMS.
キタきつね[verified]@foxbookActive Exploitation
CISA announced the addition of five CVEs that are actively exploited to its catalog, confirming real‑world attacks but providing no patches, POCs, or exploit tools.