Recently, two critical security flaws were discovered in Kentico Xperience 13, a popular digital experience platform (CMS). Tracked as CVE-2025-2746 and CVE-2025-2747, these vulnerabilities allow unauthenticated attackers to bypass the Staging Sync Server’s authentication, potentially gaining administrative control over the CMS. Both issues carry a CVSS score of 9.8 (Critical) (Warning: Multiple Critical & High…
First seen on securityboulevard.com
Jump to article: securityboulevard.com/2025/03/exploited-kentico-xperience-staging-service-authentication-bypass-vulnerabilities-cve-2025-2746-cve-2025-2747/