MetInfo CMS CVE-2026-29014 Exploited for Remote Code Execution Attacks
ID: abe231cd-0005-5dc7-9748-6bb15f178c9f
STIX ID: report--abe231cd-0005-5dc7-9748-6bb15f178c9f
Feed Name: The Hacker News
Threat Score
**CVE-2026-29014** is a critical (CVSS 9.8) unauthenticated PHP code injection vulnerability in the MetInfo CMS that allows remote attackers to execute arbitrary PHP code; patches were released on April 7, 2026, but exploitation was observed from April 25 with a surge on May 1 focused on China and Hong Kong, and about 2,000 instances of MetInfo are accessible online.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
