Critical TYPO3 Extension Exploit: Content Element Selector Flaw (CVE-2026-46725) Triggers Unauthenticated RCE
ID: 8baa78d2-5c44-5ecb-918c-4ec78d86ec76
STIX ID: report--8baa78d2-5c44-5ecb-918c-4ec78d86ec76
Feed Name: securityonline.info
Critical unauthenticated RCE (CVE-2026-46725, CVSS 9.2) has been disclosed in the third-party TYPO3 extension `mmc/ceselector` due to insecure deserialization of cookie data; exploitation requires the content element to be configured with `Persistent Mode:Static`. Multiple legacy and active versions are affected and maintainers have published patched releases via Packagist, the TYPO3 extension manager, and direct ZIP downloads—administrators should verify configurations and apply updates immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
