Known Exploited Vulnerability: CVE-2021-32648

October CMS Improper Authentication

Catalog version: 2026.07.16 Date added: 2022-01-18 Due date: 2022-02-01 CISA catalog

Vendor: October CMS

Product: October CMS

Required action: Apply updates per vendor instructions.

Known ransomware campaign use: Unknown

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-32648

CWEs

cvelogic Threat Intelligence