PatchSiren cyber security CVE debrief
CVE-2025-60236 EMV CVE debrief
A critical Deserialization of Untrusted Data vulnerability was discovered in EMV Creatify, allowing for Object Injection. This issue affects Creatify versions from n/a through 1.5. The vulnerability has a CVSS score of 9.8, indicating a high severity. The CVE was published on 2026-06-17T14:17:31.320Z and last modified on 2026-06-17T15:16:36.183Z. Organizations using Creatify should take immediate action to mitigate this vulnerability.
- Vendor
- EMV
- Product
- Creatify
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-17
- Original CVE updated
- 2026-06-17
- Advisory published
- 2026-06-17
- Advisory updated
- 2026-06-17
Who should care
Administrators and users of EMV Creatify, especially those using versions 1.5 or earlier, should be aware of this critical vulnerability and take necessary actions to secure their systems.
Technical summary
The Deserialization of Untrusted Data vulnerability in EMV Creatify allows for Object Injection, which can lead to arbitrary code execution. The vulnerability is caused by the deserialization of untrusted data, which can be exploited by an attacker to inject malicious objects. The CVSS vector for this vulnerability is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
Defensive priority
critical
Recommended defensive actions
- Update Creatify to the latest version, if available.
- Apply patches or hotfixes provided by the vendor, if available.
- Restrict access to the affected systems and limit the attack surface.
- Implement input validation and sanitization to prevent deserialization of untrusted data.
- Monitor systems for suspicious activity and implement incident response plans.
- Consider using a Web Application Firewall (WAF) to detect and prevent attacks.
- Review and update security policies and procedures to ensure secure coding practices.
Evidence notes
The information provided is based on the CVE record and NVD details. The CVE was published on 2026-06-17T14:17:31.320Z and last modified on 2026-06-17T15:16:36.183Z. The vulnerability is classified as CWE-502.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-60236 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-60236
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-60236 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-60236
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.