Alert: Critical Craft CMS Zero-Day Attacks Compromise Hundreds of Servers
Critical vulnerabilities in Craft CMS are being actively exploited in zero-day attacks. Threat actors are chaining CVE-2024-58136 (CVSS 9.0) and CVE-2025-32432 (CVSS 10.0) to gain unauthorized server access. The second vulnerability allows unauthenticated remote code execution through the ...
