• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
metinfo cms cve 2026 29014 exploited for remote code execution attacks

MetInfo CMS CVE-2026-29014 Exploited for Remote Code Execution Attacks

You are here: Home / General Cyber Security News / MetInfo CMS CVE-2026-29014 Exploited for Remote Code Execution Attacks
May 5, 2026

Threat actors are actively exploiting a critical security flaw impacting an open-source content management system (CMS) known as MetInfo, according to new findings from VulnCheck.

The vulnerability in question is CVE-2026-29014 (CVSS score: 9.8), a code injection flaw that could result in arbitrary code execution.

“MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code,” the NIST National Vulnerability Database (NVD) states.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


“Attackers can exploit insufficient input neutralization in the execution path to achieve remote code execution and gain full control over the affected server.”

Per security researcher Egidio Romano, who discovered the vulnerability, the problem is rooted in the “/app/system/weixin/include/class/weixinreply.class.php” script, and stems from a lack of adequate sanitization of user-supplied input when issuing Weixin (aka WeChat) API requests.

Cybersecurity

As a result, remote, unauthenticated attackers could exploit this loophole to inject and execute arbitrary PHP code. One key prerequisite for successful exploitation when MetInfo is running on non-Windows servers is that the “/cache/weixin/” directory has to exist beforehand.The directory is created when installing and configuring the official WeChat plugin. 

Patches for CVE-2026-29014 were released by MetInfo on April 7, 2026. The vulnerability has since come under exploitation as of April 25, with a “small number of exploits” deployed against susceptible honeypots located in the U.S. and Singapore.

Although these efforts were initially sparse and associated with automated probing, the activity witnessed a surge on May 1, 2026, focusing on China and Hong Kong IP addresses, Caitlin Condon, vice president of security research at VulnCheck, said. As many as 2,000 instances of MetInfo CMS are accessible online, most of which are in China.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


Some parts of this article are sourced from:
thehackernews.com

Previous Post: «we scanned 1 million exposed ai services. here's how bad We Scanned 1 Million Exposed AI Services. Here’s How Bad the Security Actually Is
Next Post: The Back Door Attackers Know About — and Most Security Teams Still Haven’t Closed the back door attackers know about — and most security»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • The Back Door Attackers Know About — and Most Security Teams Still Haven’t Closed
  • MetInfo CMS CVE-2026-29014 Exploited for Remote Code Execution Attacks
  • We Scanned 1 Million Exposed AI Services. Here’s How Bad the Security Actually Is
  • ScarCruft Hacks Gaming Platform to Deploy BirdCall Malware on Android and Windows
  • Weaver E-cology RCE Flaw CVE-2026-22679 Actively Exploited via Debug API May 05, 2026 Vulnerability / Network Security A critical security vulnerability in Weaver (Fanwei) E-cology , an enterprise office automation (OA) and collaboration platform, has come under active exploitation in the wild. The vulnerability ( CVE-2026-22679 , CVSS score: 9.8) relates to a case of unauthenticated remote code execution affecting Weaver E-cology 10.0 versions prior to 20260312. The issue resides in the "/papi/esearch/data/devops/dubboApi/debug/method" endpoint that allows an attacker to execute arbitrary commands by invoking exposed debug functionality. "Attackers can craft POST requests with attacker-controlled interfaceName and methodName parameters to reach command-execution helpers and achieve arbitrary command execution on the system," according to a description of the flaw in the NIST National Vulnerability Database (NVD). The advisory also noted that the Shadowserver Foundation observed the first signs of active exploitation on March 31, 2026. Chinese security vendor QiAnXin said it w…
  • Microsoft Details Phishing Campaign Targeting 35,000 Users Across 26 Countries
  • Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools
  • Progress Patches Critical MOVEit Automation Bug Enabling Authentication Bypass
  • ⚡ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & More
  • 2026: The Year of AI-Assisted Attacks

Copyright © TheCyberSecurity.News, All Rights Reserved.