Back to News & Press

Press Release

Searchlight Cyber Uncovers High-Severity Vulnerability in Open-Source Web Content Management Platform, DNN

Share on social

July 8, 2025

Lorem ipsum

Table of contents

Share on social

Join the newsletter
Searchlight Cyber Uncovers High-Severity Vulnerability in Open-Source Web Content Management Platform, DNN

The vulnerability is present in multiple software versions (6.0.0 - 10.0.1) and has a severity score of 8.6

Brisbane, Australia, July 8, 2025

The Assetnote Security Research Team at Searchlight Cyber has uncovered a high severity (CVSS 8.6) vulnerability in the open-source web content management platform DNN (formerly known as DotNetNuke), tracked as CVE-2025-52488. A detailed research post demonstrates how a series of malicious interactions can expose NTLM hashes, which in some cases can be relayed to authenticate to systems that accept NTLM-based authentication. DNN has patched the vulnerability following Searchlight’s disclosure.

DNN is a long-standing open-source content management system, established in 2003, written in C# (.NET), and maintained by an active community. It is believed to be used in more than 50,000 websites, including many enterprises.

Searchlight disclosed the vulnerability CVE-2025-52488 in April 2025. The vulnerability was uncovered through the exploitation of a series of quirks in Microsoft .Net. Ultimately, undertaking this series of actions could have exposed NTLM credentials to an unauthorized actor. The vulnerability is present in software versions 6.0.0 onwards, and has been patched in version 10.0.01.

Shubham Shah, SVP of Research and Engineering at Searchlight Cyber said: “This vulnerability was a complex discovery for our team, as a perfect combination of issues had to align for it to be exploitable. Nevertheless, the bug has existed within DNN across a wide version range and, if it had been identified by a cybercriminal, the damage could have been severe. Enterprises using DNN should update to the latest version immediately.”

Searchlight Cyber’s security research team continues to perform novel zero-day and N-day security research to ensure maximum coverage and care for its customers’ attack surfaces. All research is integrated into its Attack Surface Management platform, Assetnote, which continuously monitors, detects, and proves the exploitability of exposures before threat actors can use them.

ENDS

About Searchlight Cyber

Searchlight Cyber was founded in 2017 with a mission to stop threat actors from acting with impunity. Its External Cyber Risk Management Platform helps organizations to identify and protect themselves from emerging cybercriminal threats with Attack Surface Management and Threat Intelligence tools designed to separate the signal from the noise. Find out more at www.slcyber.io.

Related Press Releases

Searchlight Cyber Launches Preemptive Threat Exposure Management Platform to Help Organizations Outpace AI-Accelerated Attacks

Press Release

Read press release

August 12, 2026

Searchlight Cyber Launches Preemptive Threat Exposure Management Platform to Help Organizations Outpace AI-Accelerated Attacks

Searchlight Cyber Appoints Paul Ciesielski as Chief Revenue Officer

Press Release

Read press release

June 11, 2026

Searchlight Cyber Appoints Paul Ciesielski as Chief Revenue Officer

Searchlight Cyber Named a Finalist at the 2026 Cyber Risk Awards

Press Release

Read press release

April 27, 2026

Searchlight Cyber Named a Finalist at the 2026 Cyber Risk Awards

Searchlight Cyber Report: Ransomware Groups Claimed Record Number of Victims in 2025 with 30% Annual Increase

Press Release

Read press release

February 17, 2026

Searchlight Cyber Report: Ransomware Groups Claimed Record Number of Victims in 2025 with 30% Annual Increase

Searchlight Cyber Appoints Michael Gianarakis as CEO

Press Release

Read press release

February 4, 2026

Searchlight Cyber Appoints Michael Gianarakis as CEO

Searchlight Cyber Launches Ransomware File Explorer to Enable Pre-Emptive Detection of Leaked Data

Press Release

Read press release

January 22, 2026

Searchlight Cyber Launches Ransomware File Explorer to Enable Pre-Emptive Detection of Leaked Data

Never miss a beat

Get all news and updates about Searchlight Cyber, directly in your inbox.

Subscribe
Please enter a valid email address.
Background Gradient