HIGHVulnerability
Verified
Global

CISA KEV: Kentico Kentico Xperience — Kentico Xperience Path Traversal Vulnerability

·Source: CISA KEV

Updated:

Executive Summary

Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations.

Analysis

Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations. Added to CISA Known Exploited Vulnerabilities catalog on 2026-04-20. Remediation due: 2026-05-04.

Indicators of Compromise (1)

CVE (1)
CVE-2025-2749
Source Attribution

Originally published by CISA KEV on Apr 20, 2026. Verified by: CISA.

Related Threats