BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

MetInfo CMS Under Attack via Critical Code Flaw

Critical MetInfo CMS flaw exploited, granting attackers remote server control.

  • Threat actors are actively exploiting CVE-2026-29014, a critical code injection flaw in MetInfo CMS.
  • The vulnerability allows remote, unauthenticated attackers to execute arbitrary PHP code and gain full server control.
  • Exploitation activity surged on May 1, 2026, targeting honeypots in China and Hong Kong.

Threat actors are actively exploiting a critical security flaw in the popular MetInfo content management system, according to new findings from VulnCheck in May 2026. The vulnerability, a severe code injection flaw, grants attackers remote control over affected servers.

- Advertisement -

Specifically, the flaw is CVE-2026-29014, which has a maximum CVSS score of 9.8. The NIST National Vulnerability Database states it allows “remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code.”

Security researcher Egidio Romano discovered the vulnerability, which stems from insufficient input sanitization in a WeChat API script. Consequently, this lack of neutralization enables remote code execution.

One key prerequisite for exploitation on non-Windows servers is the existence of a specific directory created by the official WeChat plugin. Patches for the flaw were released by MetInfo on April 7, 2026.

However, exploitation began shortly thereafter, with a small number of automated probes detected on April 25. Activity then witnessed a significant surge on May 1, 2026, according to VulnCheck‘s Caitlin Condon.

- Advertisement -

Condon said the recent surge focused on honeypots with China and Hong Kong IP addresses. Meanwhile, as many as 2,000 instances of MetInfo CMS remain accessible online, most located in China.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Palo Alto VPN Flaw Exploited to Bypass Authentication

Palo Alto Networks has confirmed active exploitation of a critical VPN vulnerability, CVE-2026-0257, allowing...

SEC Approves T. Rowe Price Active Crypto ETF with SHIB, DOGE

The SEC approved a rule change for T. Rowe Price's Active Crypto ETF, expanding...

Michael Burry Adds to PayPal Stake Amid AI Frenzy

Famed 'The Big Short' investor Michael Burry announced he increased his stake in Paypal...

Bitcoin Mining Difficulty Sees 10% Drop, Easing Miner Pressure

Bitcoin mining difficulty plunged by 10.09% on Sunday, marking the network's 11th-largest downward adjustment.The...

Micron Stock Bull vs. Bear Debate Intensifies Amid AI Rally

Micron's stock soared over 900% in a year, briefly reaching a trillion-dollar valuation, driven...

Must Read

9 DePIN Programs For Passive Income

Here’s something most people don’t realize: your smartphone and PC can generate passive income with almost no effort.I’m not talking about clicking ads for...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading