References https://nvd.nist.gov/vuln/detail/CVE-2025-2746 https://labs.watchtowr.com/bypassing-authentication-like-its-the-90s-pre-auth-rce-chain-s-in-kentico-xperience-cms/ https://www.rapid7.com/db/vulnerabilities/kentico-xperience-cve-2025-2746/ https://www.ionix.io/blog/authentication-bypass-vulnerabilities-cve-2025-2746-cve-2025-2747/ https://devnet.kentico.com/download/hotfixes https://github.com/watchtowrlabs/kentico-xperience13-AuthBypass-wt-2025-0011 https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-2746 https://github.com/advisories/GHSA-h4vh-mhxh-6rrr https://www.tenable.com/cve/CVE-2025-2746 https://avd.aliyun.com/detail?id=AVD-2025-2746
Related VulnerabilitiesPoCibm-websphere-ssrf: IBM WebSphere HCL Digital Experience - Server-Side Request ForgeryPoCCVE-2025-49533: Adobe Experience Manager Forms - Insecure DeserializationPoCaem-anonymous-write: Adobe Experience Manager (AEM) - Anonymous JCR Node Creation(CVE-2025-54253)Adobe Experience Manager配置错误导致任意代码执行漏洞(CVE-2025-54251)Adobe Experience Manager XML注入漏洞导致安全功能绕过(CVE-2025-54249) Adobe Experience Manager SSRF漏洞导致安全功能绕过PoCCVE-2015-7823: Kentico CMS 8.2 - Open RedirectPoCCVE-2017-17736: Kentico - Installer Privilege EscalationPoCCVE-2019-10068: Kentico CMS Insecure Deserialization Remote Code ExecutionPoCCVE-2019-16469: Adobe Experience Manager - Expression Language InjectionPoCCVE-2019-8086: Adobe Experience Manager - XML External Entity InjectionPoCCVE-2021-27748: IBM WebSphere HCL Digital Experience - Server-Side Request ForgeryPoCCVE-2021-42237: Sitecore Experience Platform Pre-Auth RCE