A recently patched vulnerability in the Craft content management system (CMS) has begun to be exploited in attacks, according to a report by cybersecurity agency CISA.
See also: CISA added Linux kernel vulnerability to KEV List

The agency added CVE-2025-23209 to its list ofKnown Exploited Vulnerabilities(KEV) on Thursday. It also added a vulnerability in firewall that has already been actively exploited in the wild.
CMS Craft has a relatively small market share, but remains popular, being used by tens of thousands of websites. According to Netlas, more than 41,000 cases have been identified that are “probably” affected by the CVE-2025-23209 vulnerability.
The Craft CMS vulnerability, fixed in mid-January with the release of versions 5.5.8 and 4.13.8, is a high severity vulnerability that allows remote code execution, affecting Craft installations where the security key has already been compromised.
See also: CISA adds Oracle and Mitel vulnerabilities to KEV List
CISA added the vulnerability to the Known Exploitable Vulnerabilities (KEV) list and gave federal agencies until March 13 to address it. However, there are currently no public reports documenting attacks related to CVE-2025-23209.

On the other hand, a different vulnerability in Craft CMS, with identifier CVE-2024-56145, which also allows remote code execution, has been confirmed to be exploited by Craft developers
CVE-2024-56145 was patched in mid-November 2024, while Craft developers notified users of its active exploitation in December of that year. Despite its severity, CVE-2024-56145 has not yet been included in the CISA KEV list.
See also: CISA: Treasury Department breach did not affect other federal agencies
Cyberattacks are one of the biggest security threats in an increasingly connected digital world. They are malicious actions that target computer systems, networks and data, with the aim of stealing sensitive information, extorting money or disrupting operations. Methods such as phishing, ransomware and DDoS attacksare some of the most common forms of cyberattacks. Protecting against them requires strong security measures, such as up-to-date software, networks with secure connections and good user education.
Source: securityweek
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
