Craft CMS Chaos: Hackers Exploit Zero-Days for Data Breach Frenzy
Orange Cyberdefense’s CSIRT uncovered crafty antics as threat actors chained Craft CMS vulnerabilities in live attacks. They exploited two zero-days to breach servers, steal data, and install a PHP file manager. The Craft CMS hacking spree ended with fixes, but not before giving tech teams a real scare.

Hot Take:
Craft CMS vulnerabilities are like that one friend who always brings drama to the party—uninvited and guaranteed to cause a scene! These zero-days were exploited in the wild, making Craft CMS the star of a cybersecurity soap opera. It’s time to patch up those vulnerabilities before your server’s plot twist ends with a data heist!
Key Points:
- Orange Cyberdefense’s CSIRT discovered two zero-day vulnerabilities in Craft CMS.
- The vulnerabilities are tracked as CVE-2025-32432 (RCE) and CVE-2024-58136 (input validation flaw).
- Threat actors exploited these to breach servers and install a PHP file manager.
- 35,000 Craft CMS instances were identified, with 13,000 vulnerable to attack.
- Vulnerabilities have been patched in recent updates of Craft CMS and Yii framework.
Already a member? Log in here