CISA recently added a serious Craft CMS vulnerability to its list of Known Exploitable Vulnerabilities (KEV) , confirming active exploitation in the real world. The vulnerability is tracked as CVE-2025-32432 and concerns a critical error code injection that can be used by attackers to take complete control of affected servers . Security teams and system administrators are urged to address the issue immediately before serious network breaches occur.

Craft CMS: What is the CVE-2025-32432 vulnerability?
The vulnerability, CVE-2025-32432, belongs to the CWE-94, which describes code injection due to improper input validation. When an application fails to properly validate or sanitize user-supplied input, there is a risk of malicious code being executed. In the case of Craft CMS, a popular and widely used content management system, this flaw allows a remote, unauthenticated attacker to execute arbitrary code on the underlying server.
See also: VoidStealer malware steals passwords – Chrome ABE bypass
The risks for businesses
Once an attacker gains access via remote code execution, they can essentially take complete control of the application. This includes modifying website content, accessing sensitive database files, and creating persistent backdoors that allow for continuous monitoring. Additionally, a compromised server can be used as a launching pad for spreading to an organization’s internal network, facilitating further attacks on critical infrastructure.
Active exploitation and target scanning
On March 20, 2026, CISA officially added CVE-2025-32432 to the KEV list, highlighting that the flaw is being actively exploited by threat actors. While there is currently no evidence that it is associated with any current ransomware campaigns, RCE remains one of the most sought-after types of vulnerabilities. Organizations relying on Craft CMS are considered high-priority targets. Unpatched systems are particularly vulnerable, as they are often automatically scanned by exploit kits circulating online.
See also: CISA to federal agencies: Protect yourself against DarkSword

Security recommendations and protection measures
The Binding Operational Directive (BOD 22-01) requires federal agencies to implement measures to remediate this vulnerability by April 3, 2026.Although the directive applies only to government agencies, CISA recommends that all private sector organizations follow the same strict update schedule. System administrators should apply the latest security updates provided by the vendor and actively monitor logs access for unusual behavior or unauthorized administrator access attempts. If immediate application of the update is not possible, the cloud service’s security guidelines should be followed or the vulnerable product should be temporarily discontinued.
See also: Magento: PolyShell vulnerability allows RCE and account theft

Protection strategy against threats
The CVE-2025-32432 vulnerability is a reminder of how critical it is to be constantly vigilant and quickly apply fixes in production environments. A combination of rigorous monitoring, regular updates, and implementing extra measures can drastically reduce the risk of a breach. Businesses that ignore these issues put not only their data and services at risk, but also the overall security of their network. In the world of cybersecurity, early response is the most powerful weapon against advanced threats.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
