CVE-2026-28425Disclosure(statamic / statamic)

LOWCVSS 8.0 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch statamic statamic systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authenticated control panel user with access to Antlers-enabled inputs may be able to achieve remote code execution in the application context. That can lead to full compromise of the application, including access to sensitive configuration, modification or exfiltration of data, and potential impact on availability. Exploitation is only possible where Antlers runs on user-controlled content—for example, content fields with Antlers explicitly enabled (requiring permission to configure fields and to edit entries), built-in config that supports Antlers such as Forms email notification settings (requiring configuration permission), or third-party addons that add Antlers-enabled fields to entries (for example, the SEO Pro addon). In each case the attacker must have the relevant control panel permissions. This has been fixed in 5.73.16 and 6.7.2. Users of addons that depend on Statamic should ensure that after updating they are running a patched Statamic version.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • statamic

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 2 mentions (2026-02-28); latest day: 2
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
statamic

Deep dive

Activity timeline7 mentions / 4d
01122Mentions · 2026-02-27: 1Mentions · 2026-02-28: 2Mentions · 2026-03-01: 2Mentions · 2026-03-04: 2Patch / Workaround · 2026-02-28: 1Patch / Workaround · 2026-03-04: 1Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 2Technical Details · 2026-03-01: 2Technical Details · 2026-03-04: 202-2702-2803-0103-04
Signal classification2 categories
Disclosure
571.4%
Patch
228.6%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-271
Disclosure1
2026-02-282
Disclosure1Patch1
2026-03-012
Disclosure2
2026-03-042
Disclosure1Patch1
Full discourse7 posts
  • CCB Alert@CCBalert
    Patch

    Warning: Severe vulnerability in #Statamic CMS. CVE-2026-28425 CVSS: 8.0. Successful exploitation can lead to remote code execution. When using addons depending on Statamic, make sure that after updating you are running a patched Statamic version. #RCE! #Patch #Patch #Patch

    Post summary

    The tweet warns about the high‑severity RCE vulnerability CVE‑2026‑28425 in Statamic CMS and urges users to update to the patched version.

    01000243
    7.2K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-28425 (CVSS:8.0, HIGH) is Undergoing Analysis. Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, an authenti..https://nvd.nist.gov/vuln/detail/CVE-2026-28425 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2026-28425 is a high‑severity vulnerability in Statmatic CMS affecting versions prior to 5.73.11 and 6.4.0, currently under analysis.

    0000052
    173 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A high-severity RCE (CVE-2026-28425) affects `Statamic CMS` via Antlers inputs. Admins should review access controls and prepare to update. #Statamic #RCE #CMS https://www.pulsepatch.io/posts/cve-2026-28425-statamic-cms-rce-antlers

    Post summary

    A high‑severity remote code execution vulnerability (CVE‑2026‑28425) has been disclosed in Statamic CMS via Antlers inputs; administrators are advised to review access controls and plan for updates.

    0000067
    1 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-28425: Statamic CMS Antlers Template Engine Remote Code Execution A critical Remote Code Execution (RCE) vulnerability has been identified in the Antlers template engine of Statamic CMS. The vulnerability arises from improper isolation of use... https://cvereports.com/reports/CVE-2026-28425

    Post summary

    A critical RCE vulnerability (CVE-2026-28425) was disclosed in Statamic CMS's Antlers template engine due to improper isolation, but no PoC, exploit, patch, or active exploitation details were provided.

    0000068
    33 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-28425 Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, an authenticated control panel user with access to Antler… https://www.cve.org/CVERecord?id=CVE-2026-28425

    Post summary

    CVE-2026-28425 is a vulnerability in Statmatic CMS that allows authenticated control panel users with Antler access to exploit the system, and it has been fixed in versions 5.73.11 and 6.4.0.

    00000101
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28425 Remote Code Execution in Statamic CMS via Authenticated Antlers-Enabled Inputs https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28425

    Post summary

    The post announces a new RCE vulnerability (CVE-2026-28425) in Statamic CMS that exploits authenticated Antlers-enabled inputs, with no PoC, exploit code, or evidence of active exploitation provided.

    0000062
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-28425 - High Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, an authenticated control panel user with access to Antlers-enabled inputs may be a... https://www.thehackerwire.com/vulnerability/CVE-2026-28425/ https://t.co/epUYIi2rEF

    Post summary

    The post announces a high‑severity vulnerability (CVE‑2026‑28425) in Statmatic CMS, referencing a vulnerability article that likely contains further details.

    0000052
    119 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appstatamicstatamic---

Explore more