CVE-2025-54068Active Exploitation(laravel / livewire)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch laravel livewire systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achieve remote command execution in specific scenarios. The issue stems from how certain component property updates are hydrated. This vulnerability is unique to Livewire v3 and does not affect prior major versions. Exploitation requires a component to be mounted and configured in a particular way, but does not require authentication or user interaction. This issue has been patched in Livewire v3.6.4. All users are strongly encouraged to upgrade to this version or later as soon as possible. No known workarounds are available.

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-04-03. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-94

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • livewire

Threat summary

  • Active exploitation appears in 27 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 53 mentions across 29 observed days

What's happening

  • Active exploitation reported across 27 signals
  • Exploit tool or code specified in 7 signals
  • PoC mentioned or linked in 8 signals
  • Patch or workaround mentioned in 14 signals
  • Technical details provided in 32 signals
  • General: 9 classified signals
  • Disclosure: 7 classified signals
  • Peaked 19d ago at 5 mentions (2026-03-20); latest day: 1
  • 53 total mentions across 29 days

Affected systems

Vendors
Products
livewire

Deep dive

Activity timeline53 mentions / 29d
01345Mentions · 2026-01-28: 1Mentions · 2026-02-01: 1Mentions · 2026-02-02: 4Mentions · 2026-02-04: 2Mentions · 2026-02-05: 1Mentions · 2026-02-06: 1Mentions · 2026-02-08: 1Mentions · 2026-02-19: 1Mentions · 2026-02-28: 1Mentions · 2026-03-20: 5Mentions · 2026-03-21: 5Mentions · 2026-03-22: 3Mentions · 2026-03-23: 3Mentions · 2026-03-25: 1Mentions · 2026-03-27: 1Mentions · 2026-04-06: 2Mentions · 2026-04-08: 1Mentions · 2026-04-21: 1Mentions · 2026-05-03: 1Mentions · 2026-05-04: 1Mentions · 2026-05-26: 2Mentions · 2026-06-03: 1Mentions · 2026-06-23: 1Mentions · 2026-06-24: 2Mentions · 2026-06-25: 5Mentions · 2026-06-27: 1Mentions · 2026-07-06: 2Mentions · 2026-07-12: 1Mentions · 2026-10-01: 1PoC Mentioned / Linked · 2026-02-08: 1PoC Mentioned / Linked · 2026-03-23: 1PoC Mentioned / Linked · 2026-05-03: 1PoC Mentioned / Linked · 2026-05-04: 1PoC Mentioned / Linked · 2026-06-23: 1PoC Mentioned / Linked · 2026-06-27: 1PoC Mentioned / Linked · 2026-07-06: 1PoC Mentioned / Linked · 2026-07-12: 1Exploit Tool / Code · 2026-02-08: 1Exploit Tool / Code · 2026-03-22: 1Exploit Tool / Code · 2026-05-03: 1Exploit Tool / Code · 2026-05-04: 1Exploit Tool / Code · 2026-06-23: 1Exploit Tool / Code · 2026-06-25: 1Exploit Tool / Code · 2026-07-06: 1Active Exploitation · 2026-01-28: 1Active Exploitation · 2026-02-01: 1Active Exploitation · 2026-02-02: 2Active Exploitation · 2026-02-19: 1Active Exploitation · 2026-03-20: 1Active Exploitation · 2026-03-21: 1Active Exploitation · 2026-03-22: 3Active Exploitation · 2026-03-23: 3Active Exploitation · 2026-03-25: 1Active Exploitation · 2026-03-27: 1Active Exploitation · 2026-05-26: 2Active Exploitation · 2026-06-03: 1Active Exploitation · 2026-06-23: 1Active Exploitation · 2026-06-24: 2Active Exploitation · 2026-06-25: 5Active Exploitation · 2026-06-27: 1Patch / Workaround · 2026-01-28: 1Patch / Workaround · 2026-02-01: 1Patch / Workaround · 2026-03-20: 1Patch / Workaround · 2026-03-21: 2Patch / Workaround · 2026-03-22: 2Patch / Workaround · 2026-03-23: 2Patch / Workaround · 2026-04-08: 1Patch / Workaround · 2026-04-21: 1Patch / Workaround · 2026-05-03: 1Patch / Workaround · 2026-06-03: 1Patch / Workaround · 2026-06-24: 1Technical Details · 2026-02-02: 1Technical Details · 2026-02-04: 2Technical Details · 2026-02-08: 1Technical Details · 2026-02-19: 1Technical Details · 2026-03-20: 4Technical Details · 2026-03-21: 4Technical Details · 2026-03-22: 3Technical Details · 2026-03-23: 3Technical Details · 2026-03-27: 1Technical Details · 2026-04-06: 2Technical Details · 2026-04-08: 1Technical Details · 2026-04-21: 1Technical Details · 2026-05-04: 1Technical Details · 2026-05-26: 1Technical Details · 2026-06-03: 1Technical Details · 2026-06-23: 1Technical Details · 2026-06-24: 1Technical Details · 2026-06-25: 2Technical Details · 2026-07-12: 101-2802-0202-0502-0802-2803-2103-2303-2704-0805-0305-2606-2306-2507-0610-01
Signal classification6 categories
Active Exploitation
2751.9%
General
917.3%
Disclosure
713.5%
Patch
47.7%
PoC
47.7%
Exploit
11.9%
Referenced assets46 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-281
Active Exploitation1
2026-02-011
Active Exploitation1
2026-02-024
Active Exploitation2General2
2026-02-042
Disclosure1General1
2026-02-051
General1
2026-02-061
General1
2026-02-081
Exploit1
2026-02-191
Active Exploitation1
2026-02-281
General1
2026-03-205
Active Exploitation1Disclosure3General1
2026-03-215
Active Exploitation1Disclosure1General1Patch2
2026-03-223
Active Exploitation3
2026-03-233
Active Exploitation3
2026-03-251
Active Exploitation1
2026-03-271
Active Exploitation1
2026-04-062
Disclosure2
2026-04-081
Patch1
2026-04-211
Patch1
2026-05-031
PoC1
2026-05-041
PoC1
2026-05-262
Active Exploitation2
2026-06-031
Active Exploitation1
2026-06-231
Active Exploitation1
2026-06-242
Active Exploitation2
2026-06-255
Active Exploitation5
2026-06-271
Active Exploitation1
2026-07-062
General1PoC1
2026-07-121
PoC1
Full discourse20 posts
  • DarkShadow@darkshadow2bd
    Exploit

    Laravel-livewire RCE (CVE-2025-54068) - Video POC Here is the Exploit Github repo: https://github.com/synacktiv/Livepyre ~credit synacktiv For more bugbounty content Join my telegram channel: http://t.me/ShellSec https://t.co/XxjlowowWt

    Post summary

    The text announces a Video PoC and provides a GitHub repository containing a functional exploit for the Laravel‑livewire RCE (CVE-2025-54068).

    439121817214.1K
    6.1K followersView on X
  • Mehrab | SEO Mode@mehrab_build
    Active Exploitation

    I JUST GOT HACKED TLDR: my old Micro SaaS was running smoothly and had a good position in Google. It got hacked because of a vulnerability in an old version of Livewire (v3.4.9) due to CVE-2025-54068. The attacker created tons of spam pages and set up permanent redirects to casino websites (classic black hat SEO). They also used an indexer to get all these pages into Google. I deleted the whole website for now and I'm going to nuke the server, and try to recover it. Full Story: I woke up this morning and noticed a weird email from Google Search Console. One of my old websites that was running smoothly and generating a few bucks every month had indexing issues. But I never had indexing issues on this website! It's a pretty small micro-SaaS targeting 10 bottom-of-funnel keywords and generating tiny revenue on the side. So I opened Search Console to see which page was causing issues, and I saw this: 3.99k new pages indexed, and 3.31k more waiting to be indexed! I immediately knew something was wrong. I SSH'd into the server, and yes, just as I thought, there were malicious files in my project's public folder. The attack was actually pretty smart!! First, they modified the index.php in the public folder and added encrypted code at the very top. But at the end of it, they included the normal Laravel bootstrap code. So when you use the tail command, or even cat (I use tmux), you probably won't see the first part of the code at first glance. Everything looks normal. But that first part of the code was preventing Laravel from running. Instead, it was running a tiny WordPress installation. They used this WordPress setup to first replicate my entire website template! So if I opened the website normally, I wouldn't notice any changes. Then they used the same WordPress to create all those spam pages and redirects. This project was running Laravel 10 and Livewire 3.4.9, and I hadn't updated it in a long time. In my opinion, it was running smoothly and had no problems! But I didn't know there was a critical vulnerability in this version of Livewire that allows unauthenticated RCE access. Attackers used it to slowly ruin everything. Now I have to nuke the server because I had two other projects running on it, and I'm not sure if they're affected or not. Then I'll probably have to rebuild this whole product with a newer version so I can feel more confident about security. And regarding SEO, it probably already had a huge negative effect on my rankings. But it is what it is. Here's my plan to hopefully fix it: 1. Download all the indexed spam pages, create a clean list of URLs that aren't mine, and manually request removal in Search Console 2. Recreate the legitimate pages and make sure to add proper canonical meta tags 3. Request new indexing and wait a few days to see results 4. Maybe build a few backlinks as well, once the spam pages are deleted Lesson learned: Never stop updating your dependencies, even if everything seems fine 🙂

    Post summary

    The author reports real‑world exploitation of CVE-2025-54068 in a Laravel/Livewire app, leading to spam page injection and SEO damage, but provides no PoC, exploit code, patch, or workaround.

    218313010620.4K
    2.9K followersView on X
  • Lu3ky13 ⚡️⚡️@lu3ky13
    PoC

    Laravel Livewire RCE (CVE-2025-54068) & APP_KEY Leakage PoC. I've just released a repository containing scripts to demonstrate how leaked APP_KEYs can lead to full Remote Code Execution in Laravel Livewire apps. 🔗 https://github.com/Lu3ky13/Laravel-Livewire-Remote-Code-Execution-RCE-via-APP_KEY-Leakage #Laravel #BugBounty #RCE #CVE

    Post summary

    A repository of PoC scripts has been released, showing that exposed APP_KEYs in Laravel Livewire allow full remote code execution.

    3230104896.9K
    15.3K followersView on X
  • Nicolas Krassas@Dinosn
    Active Exploitation

    CVE-2025-54068 Laravel Livewire Credential Theft Campaign: 6,000+ Applications Compromised https://www.imperva.com/blog/cve-2025-54068-laravel-livewire-credential-theft-campaign-6000-applications-compromised/

    Post summary

    CVE‑2025‑54068 is being actively exploited in a credential‑theft campaign that has compromised over 6,000 Laravel Livewire applications.

    07035185.1K
    159.6K followersView on X
  • Synacktiv@Synacktiv
    PoC

    Back from @passthesaltcon🧂 Our team presented: 💥 Livewire RCE (CVE-2025-54068) – @_remsio_ & @_Worty 🔍 Dicozorus for smarter web fuzzing – @us3r777 💥 BadUSB Forensics – @acervoise Tools 👇 https://github.com/synacktiv/Livepyre https://github.com/synacktiv/dicozorus Thanks to the organizers and everyone who joined! 🙌

    Post summary

    The team showcased the Livewire RCE (CVE-2025-54068) and Dicozorus during a conference, sharing proof‑of‑concept code via GitHub links, with no indication of active exploitation or patch availability.

    11003674.0K
    21.5K followersView on X
  • Franso@Fransosiche
    General

    LE WEB A CASSÉ en DÉCEMBRE 2025. React2Shell, MongoBleed, Livewire... les piliers d'Internet se sont effondrés. 💥 J'ai invité les chercheurs de chez @Synacktiv, @_Worty et @_remsio_, pour décortiquer la RCE sur Livewire (CVE-2025-54068)🛠️ https://youtu.be/SZw5B-IJvHo https://t.co/yOEYnNeDos

    Post summary

    The tweet promotes a YouTube discussion where researchers dissect the CVE‑2025‑54068 Remote Code Execution vulnerability in Livewire, but it does not provide PoC, exploit tools, active exploitation evidence, or patch information.

    11112123.8K
    1.0K followersView on X
  • 🦆 SchizoDuckie 🦆@SchizoDuckie
    Active Exploitation

    Got pwned by Indonesians exploiting CVE-2025-54068 and as a thank you I'm gonna send take down requests for their whole infra tonight https://t.co/AQYof9tjj7

    Post summary

    The tweet reports a real‑world exploitation of CVE‑2025‑54068 by Indonesian actors, but provides no technical details, PoC, or patch information.

    2201821.6K
    2.8K followersView on X
  • Victor@echo_vick
    Active Exploitation

    It has everything to do with file uploads. After investigating the exploit on my server, there were clear traces of a file-upload attack, 20+ webshells sitting in storage directories, all using fake extensions. If this were CVE-2025-54068 leading to RCE, there’d be no reason to upload persistent webshells. The attacker would simply execute commands directly. The attack pattern I observed doesn’t match that CVE at all. CVE-2025-54068 results in immediate RCE without the need for uploaded shells. That’s why I’m confident about what happened, because this is based on direct investigation of my own server, you can stop trying to dismiss my findings now. Thank you.

    Post summary

    The author reports evidence of a file‑upload based webshell attack on their server and argues that the observed activity does not match CVE‑2025‑54068, suggesting the CVE is not the root cause, but no PoC, patch or exploit code is provided.

    2101721.1K
    4.7K followersView on X
  • Synacktiv@Synacktiv
    General

    📚 You can find the associated resources here: ▪️ Finding the Needle in the Haystack with Dicozorus : https://www.synacktiv.com/sites/default/files/2026-07/dicozorus_passthesalt_2026.pdf ▪️ CVE-2025-54068: Deep drive into Livewire : https://www.synacktiv.com/sites/default/files/2026-07/pts_2026_livewire.pdf ▪️ BadUSB forensic : https://archives.pass-the-salt.org/Pass%20the%20SALT/2026/slides/PTS2026-RUMP-01-BadUSB-forensic.pdf

    Post summary

    The entry merely lists three PDF resources related to a CVE and other topics, without detailed technical info, PoC references, or exploitation reports.

    10055942
    21.5K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2025-54068 - critical 🚨 Laravel Livewire v3 - Remote Command Execution > Livewire v3 (Laravel) contains a vulnerability in its component hydration/update mech... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-54068 @pdnuclei #NucleiTemplates #cve

    Post summary

    CVE-2025-54068 is a remote command execution vulnerability affecting Laravel Livewire v3’s component hydration/update process; no exploit or patch information is provided.

    02054332
    890 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    CVE-2025-54068, a critical unauthenticated RCE in Laravel Livewire v3 up to v3.6.3, has been actively exploited in a mass credential theft campaign hitting 6,000+ applications across e-commerce, healthcare, finance, and government. Key findings: - The vulnerability lives in Livewire's hydration process: the framework fails to verify submitted component state before deserializing it, letting an unauthenticated attacker inject a PHPGGC gadget chain via a crafted HTTP request and achieve RCE. No auth required, fully automated at scale (T1190). - Once in, the attacker curls shoc.enz (SHA256: 548c3672fd3201dab56f714fdd5812bb024980815b3a2b6299f0126bdf16fb3e) from hxxps://xantibot[.]pw/database-sell/shoc.enz and pipes it to bash. The 5,269-byte script recursively hunts every .env file on the filesystem (T1083, T1552.001), stages and zips them, then exfiltrates to FTP at 47.129.100[.]149, Telegram, and GoFile before wiping the staging directory (T1070.004). - Recovered exfiltration infrastructure held credentials from 6,167 apps: 381 valid AWS IAM keys, 188 live Stripe secret keys, 14,566 real database passwords, 7,176 SMTP passwords, and 1,851+ full database dumps confirming active post-theft exploitation. #DFIR_Radar

    Post summary

    CVE-2025-54068 is an unauthenticated RCE in Laravel Livewire that has been actively exploited in a large credential theft operation, with detailed PoC code and exploitation steps provided.

    32040604
    1.8K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(3/20追加) 🛡️No.1548 CVE-2025-31277 Apple Multiple Products Buffer Overflow Vulnerability ==================================== ✅概要 ・深刻度:重要⚠️ 8.8 (CVSS Base) / CISA-ADP ・種別:バッファ境界の不適切な制限 (CWE-119) ・CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Apple の複数製品において、悪意ある Web コンテンツの処理によりメモリ破損が発生し得る脆弱性。 ✅ChatGPTによる脆弱性評価 ・国内影響度判定:高 ・悪用難易度:中 ✅攻撃前提条件 ・被害者が細工された Web コンテンツを処理すること ・脆弱な Apple 製品を利用していること ✅悪用時影響 ・メモリ破損 ・任意コード実行の可能性 ・端末侵害の初期侵入点化 ✅悪用事例等に関する公開情報 ・PoC/Exploit:確認できず ・ITW:あり(Google Threat Intelligence Group が DarkSword での利用を報告。) ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-31277 https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/ https://support.apple.com/en-us/124147 🛡️No.1549 CVE-2025-43510 Apple Multiple Products Improper Locking Vulnerability ==================================== ✅概要 ・深刻度:重要⚠️ 7.8 (CVSS Base) / NVD ・種別:不適切なロック (CWE-667) ・CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 事前認証されていない攻撃者により、悪意あるアプリを介して、プロセス間で共有されるメモリに予期しない変更を生じさせる恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅攻撃前提条件 ・被害端末上で悪意あるアプリを実行させること ・脆弱な Apple 製品を利用していること ✅悪用時影響 ・共有メモリの不正変更 ・プロセス間干渉 ・後続の権限奪取やチェーン攻撃の踏み台化 ✅悪用事例等に関する公開情報 ・PoC/Exploit:確認できず ・ITW:あり(Google Threat Intelligence Group が、DarkSword の GPU サンドボックス脱出段階で使用したと説明。) ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-43510 https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/ https://support.apple.com/en-us/125632 🛡️No.1550 CVE-2025-43520 Apple Multiple Products Classic Buffer Overflow Vulnerability ==================================== ✅概要 ・深刻度:重要⚠️ 7.1 (CVSS Base) / NVD ・種別:境界外書き込み (CWE-787) / NVD、クラシックバッファオーバーフロー (CWE-120) / CISA-ADP ・CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H 事前認証されていない攻撃者により、悪意あるアプリを介して、予期しないシステム終了やカーネルメモリ書き込みを引き起こされる恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅攻撃前提条件 ・被害端末上で悪意あるアプリを実行させること ・脆弱な Apple 製品を利用していること ✅悪用時影響 ・システム異常終了 ・カーネルメモリ書き込み ・権限昇格や端末掌握の足掛かり ([NVD][6]) ✅悪用事例等に関する公開情報 ・PoC/Exploit:確認できず ・ITW:あり(GTIG が DarkSword の最終段階 `pe_main.js` において、脆弱性を悪用し物理/仮想メモリ でread/write primitive を構築すると説明) ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-43520 https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/ https://support.apple.com/en-us/125633 🛡️No.1551 CVE-2025-32432 Craft CMS Code Injection Vulnerability =================================== ✅概要 ・深刻度:緊急🔥 10.0 (CVSS Base) / NVD ・種別:コード生成の不適切な制御 (CWE-94) / GitHub, Inc. ・CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H 事前認証されていない攻撃者により、リモートからコード実行される恐れがあります。Craft CMS において、3.0.0-RC1 以上 3.9.15 未満、4.0.0-RC1 以上 4.14.15 未満、5.0.0-RC1 以上 5.6.17 未満が影響を受けます。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ✅攻撃前提条件 ・Craft CMS が外部公開されていること ・脆弱バージョンが稼働していること ・攻撃者は認証不要、ユーザー操作不要 ✅悪用時影響 ・未認証でのリモートコード実行 ・Web サーバ侵害 ・情報窃取 ・Web 改ざんや追加マルウェア設置 ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報あり ・ITW:あり(Craft CMS は 2025-04-17 に “exploited in the wild” を示唆する証拠を確認したと公表) ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-32432 https://github.com/craftcms/cms/security/advisories/GHSA-f3gw-9ww9-jmc3 https://craftcms.com/knowledge-base/craft-cms-cve-2025-32432](https://craftcms.com/knowledge-base/craft-cms-cve-2025-32432 🛡️No.1552 CVE-2025-54068 Laravel Livewire Code Injection Vulnerability ==================================== ✅概要 ・深刻度:緊急🔥 9.8 (CVSS Base) / NVD ・種別:コード生成の不適切な制御 (CWE-94) / GitHub, Inc. ・CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Livewire v3.0.0 以上 3.6.4 未満において、特定の component property update の hydration 処理に起因。事前認証されていない攻撃者により、特定条件下でリモートからコード実行される恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅攻撃前提条件 ・Livewire v3 系の脆弱バージョンが公開環境で稼働していること ・対象コンポーネントが特定の方法で mounted / configured されていること ✅悪用時影響 ・未認証でのリモートコマンド実行 ・アプリケーションサーバ侵害 ・情報窃取 ・追加マルウェア設置や横展開 ([NVD][7]) ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報あり ・ITW:あり(ThreatHunter .ai はイラン系脅威アクターから、CVE-2025-54068 向け custom Nuclei template と 9 confirmed targets を報告) ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-54068 https://github.com/livewire/livewire/security/advisories/GHSA-29cq-5w36-x7w3 https://www.threathunter.ai/blog/iranian-threat-actor-tools-techniques-iocs-ioas/ https://www.cisa.gov/news-events/alerts/2026/03/20/cisa-adds-five-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA added five known‑exploited vulnerabilities to its catalog; all have confirmed in‑the‑wild exploitation, publicly available PoCs, and vendor patches or mitigations have been released.

    030414.0K
    42.8K followersView on X
  • Remsio@_remsio_
    General

    Vous voulez en savoir plus sur la CVE-2025-54068 affectant Livewire 3 mais vous préférez un format vidéo ? Ça tombe bien ! On est passé en parler avec @_Worty dans la dernière vidéo de @Fransosiche ! 🎥

    Post summary

    The tweet merely points to a video about CVE-2025-54068 affecting Livewire 3, offering no technical details, PoC, exploit code, or patch information.

    00071514
    897 followersView on X
  • RST Cloud@rst_cloud
    Active Exploitation

    #threatreport #MediumCompleteness CVE-2025-54068 Laravel Livewire Credential Theft Campaign: 6,000+ Applications Compromised | 23-06-2026 Source: https://www.imperva.com/blog/cve-2025-54068-laravel-livewire-credential-theft-campaign-6000-applications-compromised/ Key details below ↓ 🎯Victims: E commerce, Healthcare, Financial services, Education, Government, Online gambling and betting, Logistics 🏭Industry: Government, Healthcare, E-commerce, Education, Logistic 🌐Geo: Asia, Indonesian, Asian, Brazilian 🔓CVEs: CVE-2025-54068 \[[Vulners](https://vulners.com/cve/CVE-2025-54068)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - laravel livewire (<3.6.4) 📚TTPs: ⚔️Tactics: 4 🛠️Technics: 11 🧨IOCs: - Url: 1 - File: 2 - Hash: 1 - IP: 1 - Domain: 1 - Email: 1 💽Software: Laravel Livewire, Livewire, Laravel, telegram, Unix, curl 🔢Algorithms: zip, sha256 📜Programming Languages: php #threatreport: On May 24, 2026, a major credential theft campaign exploiting CVE-2025-54068 was observed targeting Laravel Livewire applications, primarily affecting versions up to v3.6.3. This critical vulnerability arises from inadequate validation of component property updates during the hydration process, which allows unauthenticated attackers to inject malicious serialized PHP objects leading to arbitrary code execution upon deserialization. The attacker leveraged this flaw to execute a payload that fetched and executed a Bash script from their command-and-control (C2) server. The captured payload indicated that the attacker used PHPGGC gadget chains, which exploit existing legitimate PHP classes within Laravel applications. The malicious Bash shell script, identified as shoc.enz, was a lightweight 5,269 bytes in size, and served as a credential stealer. Once executed, it set up a temporary working directory, ensured no other instances were running, searched for sensitive .env files containing crucial configuration data, archived these files, and subsequently exfiltrated them to multiple C2 channels, while also cleaning up to erase forensic traces. Analysis revealed that over 6,167 applications across diverse sectors, including e-commerce, healthcare, financial services, and even governmental bodies, had their credentials compromised. The extant data included more than 1,850 database dumps and extensive email lists, indicating the active exploitation of stolen credentials. Indicators attributing the campaign to an Indonesian threat actor included linguistic elements in the malware’s code and metadata associated with the C2 infrastructure, including Telegram handles and an email address linked to multiple prior breaches in underground forums. The targeted applications encompassed a wide array of Laravel deployments, including platforms related to online gambling, education, and logistics, thereby underscoring the indiscriminate nature of the scanning efforts. Any organization utilizing unpatched Laravel Livewire v3 versions was potential prey for this extensive campaign. Overall, the operation highlights significant vulnerabilities within widely used frameworks and the severe implications of their exploitation in the cyber realm.

    Post summary

    The report documents a large-scale credential theft campaign exploiting CVE-2025-54068, detailing the exploit chain and confirming active attacks against unpatched Laravel Livewire installations.

    01051313
    770 followersView on X
  • Jonty Behr@jontybehr
    Active Exploitation

    @PovilasKorop Nothing to do with file uploads - he got pwned by the Livewire vulnerability (https://www.cvedetails.com/cve/CVE-2025-54068/)

    Post summary

    The tweet indicates that a user was compromised via CVE-2025-54068, but it contains no PoC, patch, or technical details.

    101501.5K
    1.5K followersView on X
  • Daily CyberSecurity@the_yellow_fall
    Active Exploitation

    A suspected Indonesian threat actor exploited the Laravel Livewire vulnerability (CVE-2025-54068) to steal credentials from over 6,000 web applications. #CyberSecurity #Laravel #CVE202554068 #Vulnerability #Infosec https://securityonline.info/laravel-livewire-vulnerability-cve-2025-54068 https://t.co/FAbT9yLI0I

    Post summary

    The tweet reports that an Indonesian threat actor has exploited CVE-2025-54068 in Laravel Livewire to steal credentials from more than 6,000 web applications.

    01041665
    12.8K followersView on X
  • Babacar C. DIA@babacarcissedia
    General

    just an indie dev trying to make it. Please don't try to hack me. CVE-2025-54068 is not open for this I guess monitoring do have a lot of benefits https://t.co/CPcQulRH1A

    Post summary

    The tweet merely mentions CVE-2025-54068 and states it is not open for this, without providing technical details, exploitation evidence, or mitigation information.

    001501.1K
    3.2K followersView on X
  • Victor@NduOVictor
    Active Exploitation

    Brother, these guys brought down my app for almost a week. It was a vulnerability with livewire: CVE-2025-54068 A composer update fixed it for me. I also had to beef up all my file upload validation. Also set up watchers, monitors an alerts - affliction shall not rise again.

    Post summary

    A user reports that CVE-2025-54068 caused a week's downtime of a Laravel Livewire app, which was mitigated with a composer update and strengthened file‑upload checks.

    20031358
    562 followersView on X
  • Hermes Tool@Hermes_tooll
    Active Exploitation

    CISA adds actively exploited Apple, Craft CMS, and Laravel Livewire flaws to KEV catalog — including CVE-2025-32432 (RCE), CVE-2025-54068 (MuddyWater-linked), and multiple iOS bugs used by DarkSword exploit kit. Federal agencies must patch by April 3, 2026. #CISA #KEV #RCE #CyberSecurity https://securityaffairs.com/189776/security/u-s-cisa-adds-apple-laravel-livewire-and-craft-cms-flaws-to-its-known-exploited-vulnerabilities-catalog.html

    Post summary

    CISA announced that Apple, Craft CMS, Laravel Livewire, and iOS bugs—specifically CVE‑2025‑32432 (RCE) and CVE‑2025‑54068 (MuddyWater‑linked)—are actively exploited, are listed in the KEV catalog, and must be patched by agencies by April 3, 2026.

    01022839
    3.0K followersView on X
  • Eser DENIZ@SRWieZ
    Active Exploitation

    Update your Livewire version! I heard two people report that they were hacked through an old Livewire website. CVE-2025-54068 is now actively exploited. If you're under &lt; 3.6.4, upgrade immediately.

    Post summary

    CVE-2025-54068 is currently being exploited in the wild; users of Livewire versions below 3.6.4 are urged to upgrade immediately to mitigate the risk.

    00040230
    512 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applaravellivewire---

Explore more