BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

MetInfo CMS Under Attack via Critical Code Flaw

Critical MetInfo CMS flaw exploited, granting attackers remote server control.

  • Threat actors are actively exploiting CVE-2026-29014, a critical code injection flaw in MetInfo CMS.
  • The vulnerability allows remote, unauthenticated attackers to execute arbitrary PHP code and gain full server control.
  • Exploitation activity surged on May 1, 2026, targeting honeypots in China and Hong Kong.

Threat actors are actively exploiting a critical security flaw in the popular MetInfo content management system, according to new findings from VulnCheck in May 2026. The vulnerability, a severe code injection flaw, grants attackers remote control over affected servers.

- Advertisement -

Specifically, the flaw is CVE-2026-29014, which has a maximum CVSS score of 9.8. The NIST National Vulnerability Database states it allows “remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code.”

Security researcher Egidio Romano discovered the vulnerability, which stems from insufficient input sanitization in a WeChat API script. Consequently, this lack of neutralization enables remote code execution.

One key prerequisite for exploitation on non-Windows servers is the existence of a specific directory created by the official WeChat plugin. Patches for the flaw were released by MetInfo on April 7, 2026.

However, exploitation began shortly thereafter, with a small number of automated probes detected on April 25. Activity then witnessed a significant surge on May 1, 2026, according to VulnCheck‘s Caitlin Condon.

- Advertisement -

Condon said the recent surge focused on honeypots with China and Hong Kong IP addresses. Meanwhile, as many as 2,000 instances of MetInfo CMS remain accessible online, most located in China.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Kaiko: Traders May Have Positioned Ahead of Robinhood Listings

Analytics firm Kaiko reported on Monday that trading patterns suggest some traders may have...

US Dollar Dominance Grows as Offshore Deposits Hit Record $14.5 Trillion

Offshore US dollar deposits have surged to a record high of $14.5 trillion as...

Crypto Case Deconfliction Hindered by Infrastructure Gap

Government agencies struggle with crypto case deconfliction due to an infrastructure gap, not a...

Coinbase Cuts 14% of Jobs, Citing ‘AI-First’ Restructuring

Coinbase is cutting approximately 14% of its workforce, a move CEO Brian Armstrong linked...

Bankers Say Stablecoin Yield Ban Draft Has Flaws

Major U.S. banking groups have publicly opposed the latest draft of the Clarity Act's...

Must Read

What Is the Dencun Upgrade for Ethereum?

The Dencun Upgrade for Ethereum is poised to revolutionize the blockchain landscape, offering improved scalability, efficiency, and groundbreaking features. Set to launch at the...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading