RaqibCTI
CVE

CVE-2025-2746

P2
Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability
Kentico · Xperience CMS
Date added (CISA)
2025-10-20
Remediation due
2025-11-10
Known ransomware use
Not indicated
Remediation priority
P2past CISA due date

Description

Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could allow an attacker to control administrative objects.

Source: NVD ↗ · CISA KEV Catalog ↗