BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

MetInfo CMS Under Attack via Critical Code Flaw

Critical MetInfo CMS flaw exploited, granting attackers remote server control.

  • Threat actors are actively exploiting CVE-2026-29014, a critical code injection flaw in MetInfo CMS.
  • The vulnerability allows remote, unauthenticated attackers to execute arbitrary PHP code and gain full server control.
  • Exploitation activity surged on May 1, 2026, targeting honeypots in China and Hong Kong.

Threat actors are actively exploiting a critical security flaw in the popular MetInfo content management system, according to new findings from VulnCheck in May 2026. The vulnerability, a severe code injection flaw, grants attackers remote control over affected servers.

- Advertisement -

Specifically, the flaw is CVE-2026-29014, which has a maximum CVSS score of 9.8. The NIST National Vulnerability Database states it allows “remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code.”

Security researcher Egidio Romano discovered the vulnerability, which stems from insufficient input sanitization in a WeChat API script. Consequently, this lack of neutralization enables remote code execution.

One key prerequisite for exploitation on non-Windows servers is the existence of a specific directory created by the official WeChat plugin. Patches for the flaw were released by MetInfo on April 7, 2026.

However, exploitation began shortly thereafter, with a small number of automated probes detected on April 25. Activity then witnessed a significant surge on May 1, 2026, according to VulnCheck‘s Caitlin Condon.

- Advertisement -

Condon said the recent surge focused on honeypots with China and Hong Kong IP addresses. Meanwhile, as many as 2,000 instances of MetInfo CMS remain accessible online, most located in China.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Crypto PACs Pour Millions into Texas Runoff Races

Two Texas congressional runoff elections this week are being heavily influenced by spending from...

Grayscale Names ETH, SOL, BNB, CC to Benefit from Act

Grayscale has identified four cryptocurrencies—Ethereum, Solana, BNB, and Canton—as the top beneficiaries of the...

Vitalik Buterin: Ethereum Foundation to “Shrink” as Top Exodus

Ethereum Foundation co-founder Vitalik Buterin announced the organization is shrinking to focus on core...

Bitcoin Risks $72K as Sell Pressure Mounts

Bitcoin faces a potential 7% drop toward $72,000 as bearish momentum strengthens on higher...

Ghost CMS Flaw Fuels Widespread ClickFix Malware

A critical SQL injection flaw (CVE-2026-26980) in Ghost CMS is being actively exploited to...

Must Read

How To Buy a Handshake Domain: A Step-by-Step Guide

Handshake Domains | Benefits | Drawbacks | How To Buy | Supported BrowsersIn this step-by-step guide, I am going to show you how to...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading