Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2025-2746

Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability

Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could allow an attacker to control administrative objects.

cat cve-2025-2746.json
Vendor
Kentico
Product
Xperience CMS
CVSS
9.8
EPSS (exploit probability)
58.4%
Status
kev
CISA patch-by (BOD 22-01)
Published

Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could allow an attacker to control administrative objects.

Added to CISA’s Known Exploited Vulnerabilities catalog on 2025-10-20. Required action per CISA: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Due date: 2025-11-10.

This is an auto-synced KEV catalog record pending a full 0dayNews write-up — see CISA’s KEV catalog and the NVD record linked above for primary sources.