Two critical vulnerabilities, CVE-2025-0364 and, CVE-2024-54761 have been discovered in BigAnt Server. While CVE-2024-54761 was initially misclassified, further analysis uncovered CVE-2025-0364, which lets unauthenticated attackers bypass CAPTCHA to create admin accounts and execute arbitrary PHP code via the Cloud Storage Addin, risking full system compromise. No official patch is available yet, and public exploits exist, making immediate mitigations such as disabling SaaS registration and restricting access essential.
What’s new on HivePro
Get through updates and upcoming events, and more directly in your inbox