HomeSecurityCISA: CMS Craft vulnerability exploited in attacks

CISA: CMS Craft vulnerability exploited in attacks

A recently patched vulnerability in the Craft content management system (CMS) has begun to be exploited in attacks, according to a report by cybersecurity agency CISA.

See also: CISA added Linux kernel vulnerability to KEV List

CMS Craft vulnerability

The agency added CVE-2025-23209 to its list ofKnown Exploited Vulnerabilities(KEV) on Thursday. It also added a vulnerability in firewall that has already been actively exploited in the wild.

CMS Craft has a relatively small market share, but remains popular, being used by tens of thousands of websites. According to Netlas, more than 41,000 cases have been identified that are “probably” affected by the CVE-2025-23209 vulnerability.

The Craft CMS vulnerability, fixed in mid-January with the release of versions 5.5.8 and 4.13.8, is a high severity vulnerability that allows remote code execution, affecting Craft installations where the security key has already been compromised.

See also: CISA adds Oracle and Mitel vulnerabilities to KEV List

CISA added the vulnerability to the Known Exploitable Vulnerabilities (KEV) list and gave federal agencies until March 13 to address it. However, there are currently no public reports documenting attacks related to CVE-2025-23209.

CISA: CMS Craft vulnerability exploited in attacks

On the other hand, a different vulnerability in Craft CMS, with identifier CVE-2024-56145, which also allows remote code execution, has been confirmed to be exploited by Craft developers

CVE-2024-56145 was patched in mid-November 2024, while Craft developers notified users of its active exploitation in December of that year. Despite its severity, CVE-2024-56145 has not yet been included in the CISA KEV list.

See also: CISA: Treasury Department breach did not affect other federal agencies

Cyberattacks are one of the biggest security threats in an increasingly connected digital world. They are malicious actions that target computer systems, networks and data, with the aim of stealing sensitive information, extorting money or disrupting operations. Methods such as phishing, ransomware and DDoS attacksare some of the most common forms of cyberattacks. Protecting against them requires strong security measures, such as up-to-date software, networks with secure connections and good user education.

Source: securityweek

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS