cognitive cybersecurity intelligence

News and Analysis

Search

Critical Craft CMS RCE 0-Day Vulnerability Exploited in Attacks to Steal Data

Critical Craft CMS RCE 0-Day Vulnerability Exploited in Attacks to Steal Data

A critical RCE vulnerability (CVE-2025-32432) in Craft CMS, affecting versions prior to 3.9.15, 4.14.15, and 5.6.17, is actively exploited to steal data. Attackers use a chain of vulnerabilities, prompting Craft CMS to release patches. Users should update immediately or block suspicious payloads. Compromised systems require security key resets and user credential rotations.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts