VulnerabilitiesCritical

CVE-2025-32432: Craft CMS Code Injection Vulnerability

Monday, March 23, 2026
Global
CISA KEV Catalog - CVE-2025-32432

Summary

Craft CMS contains a code injection vulnerability that allows a remote attacker to execute arbitrary code.

Threat Analysis

Craft CMS contains a code injection vulnerability that allows a remote attacker to execute arbitrary code. This vulnerability affects Craft CMS Craft CMS and has been added to CISA's Known Exploited Vulnerabilities catalog on 2026-03-20, indicating active exploitation in the wild. Organizations should prioritize patching this vulnerability immediately. Mitigation: Apply vendor patches as soon as available, implement network segmentation, and monitor for suspicious activity.

Last updated: Mar 23, 2026, 01:18 PM

Daily Intelligence

Stay Ahead of Threats

Subscribe to receive daily threat briefings delivered to your inbox. Be the first to know about emerging security risks.

No spamUnsubscribe anytimeDaily at 9 AM