LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-2749: Kentico Xperience Path Traversal Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 20, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 4, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-2749 to its Known Exploited Vulnerabilities catalog on Apr 20, 2026, with a federal patch deadline of May 4, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations.

Kentico Xperience contains a path traversal weakness that lets an authenticated user reach the Staging Sync Server and place arbitrary data into locations determined by relative paths. The issue matters because it combines improper path handling with unrestricted file operations, giving an attacker who already holds valid credentials a route to write content outside intended directories on the affected system.

How it works

The vulnerability is tracked under CWE-22 (path traversal) and CWE-434 (unrestricted upload of file with dangerous type). An authenticated user interacting with the Staging Sync Server can supply path elements that resolve outside the expected target directory. The server then writes the supplied data to the resulting location without sufficient validation of the final path. No further exploit mechanics are described in the available summary.

Am I affected? How to find it in your systems

Kentico Xperience is a web content management platform that commonly runs on Windows servers hosting ASP.NET applications. Begin by inventorying all internet-facing and internal instances of Kentico Xperience, paying particular attention to deployments that enable the Staging Sync Server feature. Review configuration files and administrative settings that control staging synchronization. Because exact affected versions are not stated here, compare installed builds directly against the vendor advisory. Look for authentication events and file-write operations tied to the staging endpoints in application and web-server logs; anomalous relative-path strings or unexpected files appearing outside normal content directories can indicate attempted abuse.

How to remediate

Apply the vendor-supplied update referenced in the official advisory as the primary remediation step. After patching, review and restrict the accounts permitted to use the Staging Sync Server, and confirm that file-upload handling follows the vendor’s current hardening guidance for this product class. Where the installation integrates with cloud services, apply any applicable requirements from CISA BOD 22-01.

If you can't patch immediately

If your data may have been exposed

Path traversal issues that permit arbitrary file placement have been used in breaches. You can run a free exposure scan of your organization’s email addresses against known breach data to check for prior incidents involving the affected environment.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedKentico · Kentico Xperience
WeaknessCWE-22
Added to CISA KEVApr 20, 2026
Federal patch deadlineMay 4, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities