🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.

Kentico Xperience Path Traversal Arbitrary File Upload (CVE-2025-2749) | MSSP Advisory

High🔴 KEV ALERT
DateMay 6, 2026
CVECVE-2025-2749
CVSS Score7.2
Affectedxperience
📋Executive Summary
CISA added CVE-2025-2749 to its Known Exploited Vulnerabilities catalog, flagging a path traversal flaw in Kentico Xperience that lets authenticated users upload arbitrary files through staging sync servers. Government agencies have until May 2026 to patch or discontinue use, which means active exploitation is already happening in commercial environments.
⚠️Why It Matters for MSSPs
Your RMM and PSA systems could be compromised if you run Kentico Xperience for client portals or internal documentation, giving attackers a foothold into your entire client base. Client environments using Kentico for their websites or content management are exposed to file upload attacks that can deploy web shells and backdoors.
Recommended Action
Audit your stack and all client environments for Kentico Xperience installations within 24 hours and apply vendor patches immediately. Contact clients running Kentico websites to schedule emergency patching or temporary service shutdowns if patches are unavailable.
🔒
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
Get your first advisory free →
🏷️Threat Category
Vulnerability Disclosure

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.