
Authenticated RCE (CVE-2026-28697) identified in `Craft CMS`. Update available for this #CMS #vulnerability. Fix in 5.9.0-beta.1 or later. https://www.pulsepatch.io/posts/cve-2026-28697-craftcms-authenticated-rce
Post summary
The post announces a patch update for the authenticated remote code execution vulnerability CVE‑2026‑28697 in Craft CMS, with no evidence of active exploitation or publicly shared PoC.


