logo

Critical TYPO3 Extension Exploit: Content Element Selector Flaw (CVE-2026-46725) Triggers Unauthenticated RCE

ID: 8baa78d2-5c44-5ecb-918c-4ec78d86ec76

STIX ID: report--8baa78d2-5c44-5ecb-918c-4ec78d86ec76

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-05-25

Date Updated: 2026-05-25

Author: Ddos

...
...

Critical unauthenticated RCE (CVE-2026-46725, CVSS 9.2) has been disclosed in the third-party TYPO3 extension `mmc/ceselector` due to insecure deserialization of cookie data; exploitation requires the content element to be configured with `Persistent Mode:Static`. Multiple legacy and active versions are affected and maintainers have published patched releases via Packagist, the TYPO3 extension manager, and direct ZIP downloads—administrators should verify configurations and apply updates immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.