Researchers uncovered severe vulnerabilities in Kentico’s Xperience CMS (WT-2025-0006, WT-2025-0007, WT-2025-0011) enabling attackers to achieve remote code execution. These flaws affect version 13 installations using username/password authentication. Attackers can exploit authentication bypasses and a path traversal issue for unauthorized access. Kentico has released patches for these vulnerabilities. Organizations are urged to upgrade immediately.

M&S issues update as crippling nationwide IT outage still ongoing – The Sun
Marks & Spencer (M&S) halted online orders in the UK and Ireland following a cyber attack, leading to a 5% drop in share price. Physical