PatchSiren cyber security CVE debrief
CVE-2025-60236 EMV CVE debrief
A critical Deserialization of Untrusted Data vulnerability was discovered in EMV Creatify, allowing for Object Injection. This issue affects Creatify versions from n/a through 1.5. The vulnerability has a CVSS score of 9.8, indicating a high severity. The CVE was published on 2026-06-17T14:17:31.320Z and last modified on 2026-06-17T15:16:36.183Z. Organizations using Creatify should take immediate action to mitigate this vulnerability.
- Vendor
- EMV
- Product
- Creatify
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-17
- Original CVE updated
- 2026-06-17
- Advisory published
- 2026-06-17
- Advisory updated
- 2026-06-17
Who should care
Administrators and users of EMV Creatify, especially those using versions 1.5 or earlier, should be aware of this critical vulnerability and take necessary actions to secure their systems.
Technical summary
The Deserialization of Untrusted Data vulnerability in EMV Creatify allows for Object Injection, which can lead to arbitrary code execution. The vulnerability is caused by the deserialization of untrusted data, which can be exploited by an attacker to inject malicious objects. The CVSS vector for this vulnerability is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
Defensive priority
critical
Recommended defensive actions
- Update Creatify to the latest version, if available.
- Apply patches or hotfixes provided by the vendor, if available.
- Restrict access to the affected systems and limit the attack surface.
- Implement input validation and sanitization to prevent deserialization of untrusted data.
- Monitor systems for suspicious activity and implement incident response plans.
- Consider using a Web Application Firewall (WAF) to detect and prevent attacks.
- Review and update security policies and procedures to ensure secure coding practices.
Evidence notes
The information provided is based on the CVE record and NVD details. The CVE was published on 2026-06-17T14:17:31.320Z and last modified on 2026-06-17T15:16:36.183Z. The vulnerability is classified as CWE-502.
Official resources
-
CVE-2025-60236 CVE record
CVE.org
-
CVE-2025-60236 NVD detail
NVD
-
Source item URL
nvd_modified
- Mitigation or vendor reference
public