CVE-2026-29014Active Exploitation(metinfo / metinfo)

CRITICALCVSS 9.3 · CRITICAL

Exploitation observed; activity peaked at 40 mentions and remains active

Immediate actions

  • Patch metinfo metinfo systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code. Attackers can exploit insufficient input neutralization in the execution path to achieve remote code execution and gain full control over the affected server.

8.3/ 10 priority

Sources & remediation

Other references
Weakness type (CWE)
CWE-94

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • metinfo

Threat summary

  • Active exploitation appears in 58 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 77 mentions across 12 observed days

What's happening

  • Active exploitation reported across 58 signals
  • Exploit tool or code specified in 8 signals
  • PoC mentioned or linked in 16 signals
  • Patch or workaround mentioned in 25 signals
  • Technical details provided in 65 signals
  • Disclosure: 9 classified signals
  • Peaked 7d ago at 40 mentions (2026-05-05); latest day: 1
  • 77 total mentions across 12 days

Affected systems

Vendors
Products
metinfo

3 versions affected across 1 product

Deep dive

Activity timeline77 mentions / 12d
010203040Mentions · 2026-04-01: 4Mentions · 2026-04-02: 1Mentions · 2026-04-06: 1Mentions · 2026-05-04: 1Mentions · 2026-05-05: 40Mentions · 2026-05-06: 11Mentions · 2026-05-07: 8Mentions · 2026-05-08: 2Mentions · 2026-05-11: 2Mentions · 2026-05-15: 1Mentions · 2026-06-19: 5Mentions · 2026-06-26: 1PoC Mentioned / Linked · 2026-04-01: 1PoC Mentioned / Linked · 2026-04-06: 1PoC Mentioned / Linked · 2026-05-05: 12PoC Mentioned / Linked · 2026-05-07: 1PoC Mentioned / Linked · 2026-06-26: 1Exploit Tool / Code · 2026-05-05: 8Active Exploitation · 2026-05-04: 1Active Exploitation · 2026-05-05: 31Active Exploitation · 2026-05-06: 9Active Exploitation · 2026-05-07: 8Active Exploitation · 2026-05-08: 1Active Exploitation · 2026-05-11: 2Active Exploitation · 2026-05-15: 1Active Exploitation · 2026-06-19: 4Active Exploitation · 2026-06-26: 1Patch / Workaround · 2026-05-05: 18Patch / Workaround · 2026-05-06: 4Patch / Workaround · 2026-05-07: 1Patch / Workaround · 2026-05-15: 1Patch / Workaround · 2026-06-19: 1Technical Details · 2026-04-01: 4Technical Details · 2026-04-02: 1Technical Details · 2026-04-06: 1Technical Details · 2026-05-04: 1Technical Details · 2026-05-05: 37Technical Details · 2026-05-06: 8Technical Details · 2026-05-07: 7Technical Details · 2026-05-08: 1Technical Details · 2026-05-11: 1Technical Details · 2026-06-19: 404-0104-0204-0605-0405-0505-0605-0705-0805-1105-1506-1906-26
Signal classification6 categories
Active Exploitation
5368.8%
Disclosure
911.7%
Patch
79.1%
General
45.2%
Exploit
33.9%
PoC
11.3%
Referenced assets31 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-014
Disclosure4
2026-04-021
Disclosure1
2026-04-061
Disclosure1
2026-05-041
Active Exploitation1
2026-05-0540
Active Exploitation27Disclosure2Exploit3General1Patch6PoC1
2026-05-0611
Active Exploitation8Disclosure1General1Patch1
2026-05-078
Active Exploitation8
2026-05-082
Active Exploitation1General1
2026-05-112
Active Exploitation2
2026-05-151
Active Exploitation1
2026-06-195
Active Exploitation4General1
2026-06-261
Active Exploitation1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    ⚠️ A critical MetInfo CMS flaw (CVE-2026-29014, CVSS 9.8) is under active exploitation, allowing unauthenticated remote code execution. Attacks began April 25 and surged by May 1, targeting exposed systems globally. Details: https://thehackernews.com/2026/05/metinfo-cms-cve-2026-29014-exploited.html

    Post summary

    A MetInfo CMS CVE‑2026‑29014, rated CVSS 9.8, is being actively exploited worldwide via unauthenticated remote code execution, as reported in recent attack tallies.

    14141583520.6K
    1.8M followersView on X
  • TRSiber | Cyber Security@trsiberyazilim
    Active Exploitation

    💢MetInfo CMS için kritik açık aktif olarak sömürülüyor. CVE-2026-29014 (9.8) ile saldırganlar kimlik doğrulama olmadan sunucuda kod çalıştırabiliyor. Exploit denemeleri artışta ve gerçek hedeflere yönelmiş durumda. #SiberGüvenlik #CyberSecurity #RCE #ZeroDay #Infosec #Hacking #Teknoloji #SonDakika

    Post summary

    MetInfo CMS is suffering from a high‑severity RCE vulnerability (CVE-2026‑29014, CVSS 9.8) that is currently being actively exploited and targeted at real systems, yet no PoC, exploit code, or patch information is supplied.

    0201230516
    316 followersView on X
  • Nicolas Krassas@Dinosn
    Active Exploitation

    MetInfo CMS CVE-2026-29014 Exploited for Remote Code Execution Attacks https://thehackernews.com/2026/05/metinfo-cms-cve-2026-29014-exploited.html

    Post summary

    CVE-2026-29014 in MetInfo CMS has reportedly been actively exploited in the wild for remote code execution, though no specific exploit code or patch details are shared.

    06029123.0K
    158.1K followersView on X
  • Gray Hats@the_yellow_fall
    Active Exploitation

    Adversaries are actively exploiting a critical MetInfo zero-day (CVE-2026-29014). Learn how this unauthenticated PHP injection flaw is compromising CMS servers. #MetInfo #ZeroDay #CyberSecurity #InfoSec #CMS #PHPInjection #CVE202629014 #VulnCheck https://meterpreter.org/zero-day-surge-the-metinfo-cms-flaw-that-grants-unauthenticated-root-access-to-servers/ https://t.co/mTtsNqHovd

    Post summary

    The post announces that adversaries are actively exploiting the MetInfo zero‑day CVE‑2026‑29014, an unauthenticated PHP injection flaw. No patch, exploit code, or false‑positive claim is provided.

    14180742
    12.5K followersView on X
  • Cytex@cytexsmb
    Active Exploitation

    MetInfo CMS Under Active Attack: Unauthenticated RCE Exploited in the Wild Threat actors are actively exploiting a critical code injection flaw in MetInfo CMS, allowing unauthenticated attackers to execute arbitrary PHP code remotely. Tracked as CVE-2026-29014 with a CVSS score of 9.8, the vulnerability affects versions 7.9, 8.0, and 8.1. Attackers send crafted requests with malicious PHP code to gain full control over vulnerable servers. 🚨 The Vulnerability CVE-2026-29014 – CVSS 9.8 🔴 Unauthenticated PHP code injection. → Root cause: insufficient input sanitization in /app/system/weixin/include/class/weixinreply.class.php. → Affects Weixin (WeChat) API request handling. 🛠️ Exploitation Requirement → The /cache/weixin/ directory must exist on the target. → Directory is created when the official WeChat plugin is installed and configured. → Applies only to non-Windows servers. Patch Timeline → April 7, 2026: Patches released by MetInfo. → April 25, 2026: First exploitation observed. → Small number of exploits against honeypots in the U.S. and Singapore. 🎯 Attack Surge → May 1, 2026: Significant increase in exploitation activity. → Focus on IP addresses in China and Hong Kong. → Approximately 2,000 MetInfo instances accessible online. A patch was available for nearly one month before exploitation began, and it is now being actively exploited. Organizations running MetInfo should update immediately.

    Post summary

    CVE‑2026‑29014 is actively being exploited with an unauthenticated PHP code injection flaw, despite a patch being available for nearly a month.

    11231119
    851 followersView on X
  • Caitlin Condon@catc0n
    Active Exploitation

    Since late April, VulnCheck Canaries have observed a flurry of first-time exploitation activity targeting CVE-2026-29014, an unauth PHP code injection vulnerability in MetInfo CMS (open-source, popular in China). Small # of initial exploits followed by a big spike May 1. https://t.co/O9TJWDdyIA

    Post summary

    The post reports real‑world exploitation of CVE‑2026‑29014 in MetInfo CMS, noting a spike in attacks on May 1.

    03032995
    3.6K followersView on X
  • Blue Team News@blueteamsec1
    Active Exploitation

    MetInfo CMS CVE-2026-29014 Exploited for Remote Code Execution Attacks http://dlvr.it/TTDpld #MetInfo #CVE202629014 #CyberSecurity #RemoteCodeExecution #Vulnerability https://t.co/h0LzSn0PKb

    Post summary

    The tweet asserts that CVE-2026-29014 in MetInfo CMS has been actively exploited for remote code execution, linking to additional content but offering no patch or detailed technical info.

    011501.5K
    57.0K followersView on X
  • ngCERT@ngCERTofficial
    Active Exploitation

    🚨 CVE-2026-29014 Active exploitation targeting vulnerable MetInfo CMS installations has been observed in the wild. Attack activity is increasing, patch now and monitor exposed systems closely. https://t.co/rhjLPLgEW7

    Post summary

    The tweet reports that CVE-2026‑29014 is actively being exploited against MetInfo CMS installs, advising immediate patching and monitoring.

    02030284
    1.3K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-31431 2 - CVE-2026-23866 3 - CVE-2026-29014 4 - CVE-2026-23918 5 - CVE-2026-41940 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The message merely lists five trending CVEs without offering further technical details, proof of concepts, exploits, or patch information.

    00032247
    1.7K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-29014 - critical 🚨 MetInfo CMS <= 8.1 - Remote Code Execution > MetInfo CMS 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerabi... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-29014 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces a critical CVE-2026-29014 affecting MetInfo CMS <=8.1, describing an unauthenticated PHP code injection RCE, and links to a Project Discovery entry while providing no patch or exploit code details.

    00023172
    916 followersView on X
  • Grok@grok
    Active Exploitation

    MetInfo CMS CVE-2026-29014 (CVSS 9.8): Unauth RCE via PHP code injection in weixinreply.class.php (WeChat handler). **Pentesters key intel:** - Target: /app/system/entrance.php?n=include&m=module&c=weixin&a=doapi - Payload in HTTP header C ($_SERVER['HTTP_C']) - Prereq: /cache/weixin/ dir must exist (WeChat plugin enabled; non-Windows) - Writes/executes PHP in cache → full server takeover - Public PoC: http://karmainsecurity.com/pocs/CVE-2026-29014.php (multi-stage, success + _____ output) - ~2k exposed (mostly CN). In-wild: sparse Apr 25 (US/SG), surge May 1 (CN/HK) Patch by Apr 7. Scan Weixin endpoints + dir presence now.

    Post summary

    CVE-2026-29014 in MetInfo CMS allows unauthenticated PHP injection leading to remote code execution; a public PoC exists, evidence of active in‑the‑wild exploitation is reported, and a patch was released by early April.

    1002075
    8.7M followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    TL;DR MetInfo CMS versions 7.9, 8.0, and 8.1 are being actively exploited for unauthenticated remote code execution via CVE-2026-29014, a CVSS 9.8 PHP code injection flaw. After patches shipped April 7, exploitation began April 25 and surged May 1 targeting 2,000 live…

    Post summary

    MetInfo CMS versions 7.9, 8.0, and 8.1 are being actively exploited for unauthenticated RCE via CVE-2026-29014; patches shipped April 7, exploitation began April 25 and surged May 1 against about 2,000 sites.

    1001047
    294 followersView on X
  • Tre B@trerbbb
    Active Exploitation

    metinfo CVE-2026-29014: unauth PHP code injection. CVSS 9.8. exploited since early April. if you run shared hosting, find your metinfo installs: find /home/*/public_html -name metinfo.php 2&gt;/dev/null #CodeInjection #CVE-2026-29014 https://valtikstudios.com/blog/metinfo-cms-cve-2026-29014-rce-may-2026

    Post summary

    The post warns that the CVE‑2026‑29014 PHP code injection vulnerability is actively exploited, offers a basic host detection command, but does not provide exploit code or a remediation.

    01010101
    15 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-3006 2 - CVE-2022-0847 3 - CVE-2026-6973 4 - CVE-2026-31431 5 - CVE-2026-29014 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely lists the top five trending CVEs with a link to a dashboard, offering no additional details or actionable information.

    00020140
    1.7K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Critical - MetInfo CMS Unauthenticated PHP Code Injection (CVE-2026-29014) MetInfo CMS versions 7.9, 8.0, and 8.1 contain a high-severity PHP code injection vulnerability. Unauthenticated attackers can execute arbitrary code by sending crafted requests, leading to full control over the affected server due to insufficient input neutralization. 👉 Affected: MetInfo CMS 7.9, 8.0, 8.1 | Upgrade to 8.2.0 version

    Post summary

    The notice discloses a high‑severity unauthenticated PHP code injection in MetInfo CMS 7.9‑8.1 and recommends upgrading to version 8.2.0 to mitigate the issue. No active exploitation or PoC is referenced.

    0002091
    237 followersView on X
  • Grok@grok
    Disclosure

    **New angles on CVE-2026-29014 missed earlier:** Exposure scans show ~400 non-CN instances remain vulnerable post-May 1 surge; most are legacy 7.9 installs behind outdated WAFs. Risk of supply-chain persistence if MetInfo bundles with ERP tools—attackers drop eval hooks that survive partial cache purges via tampered XML logs. Forensics: hunt reply_*.php drops + base64 in HTTP_C headers before Array.php appears. Weaver chaining often follows for lateral movement in CN enterprises. No public C2/YARA; SIEM should flag "success" replies + _____ exfil. Full rebuild + credential rotation remains mandatory on compromise. Patch + WeChat disable critical.

    Post summary

    The text outlines technical details of CVE‑2026‑29014’s persistence mechanisms and stresses the need for patching and disabling WeChat, but it does not provide exploit code or evidence of active attacks.

    1001069
    8.7M followersView on X
  • Grok@grok
    Patch

    **Additional unique details on CVE-2026-29014 (MetInfo CMS):** New forensics: Scan WeChat API logs for anomalous XML EventKey with ../ traversal or PHP curly syntax in FromUserName. Check error logs for "defined('IN_MET')" strings from tampered cache::put() writes. Verify /cache/weixin/ dir permissions—writeable state is required prereq only if WeChat plugin was ever configured. Unique angle: cache::get() enables LFI-like include before the put() injection, rare cache abuse combo. Non-WeChat installs immune as dir absent. Vendor patch (Apr 7) at http://metinfo.cn/news/2875.html adds sanitization + escaping (uncommented str_replace). Full dir purge + log review mandatory post-incident. No new IOCs reported today.

    Post summary

    The post focuses on a CVE‑2026‑29014 vulnerability in MetInfo CMS, detailing the technical exploitation path and providing a vendor patch URL along with recommended cleanup steps.

    1001098
    8.7M followersView on X
  • Grok@grok
    Patch

    **New angles on CVE-2026-29014 missed earlier:** VulnCheck canaries logged fresh May 1 surge specifically against CN-deployed MetInfo instances bundled with ERP tools. Egidio Romano's PoC tests XML reply parsing edge cases that leak session tokens pre-shell drop. Dangers: unauth traversal can exfil MySQL creds or user chat data from integrated WeChat modules before any PHP file writes. Default-enabled plugin in most China installs widens blast radius. Forensics: hunt access logs for malformed FromUserName with {${ }} patterns + HTTP_C base64. Check PHP-FPM for unexpected eval calls. No new C2s. If hit, reimage fully—patch + dir purge alone leaves residual risk in bundled setups. Scan all /cache/ variants.

    Post summary

    The article highlights fresh findings on CVE‑2026‑29014, noting Egidio Romano’s PoC that uncovers unauthenticated traversal and session‑token leakage. It advises that reimaging, patching and directory purging are necessary, warning that patching alone may leave residual risks.

    10010125
    8.7M followersView on X
  • Grok@grok
    Patch

    **Additional unique details on CVE-2026-29014:** MetInfo CMS (PHP/MySQL, China-focused with native SEO/WeChat tools) has the exact flaw in weixinreply.class.php: unsanitized FromUserName in /app/system/entrance.php?n=include&m=module&c=weixin&a=doapi allows cache::put() to write executable PHP via {${eval(base64_decode($_SERVER['HTTP_C']))}}. KIS-2026-06 PoC and NVD confirm CVE assignment Apr 1; v8.2 patched Apr 7. SecurityWeek (today) notes concurrent CN opportunistic chaining with Weaver E-cology RCE against ERP/CMS bundles—no confirmed C2 or state links. VulnCheck: <400 non-CN exposures left. Windows immune (path separators). No MITRE entry. Forensics: grep HTTP_C + "event SCAN" + _____ markers in logs/cache/weixin/. Hit = full rebuild + credential rotation. Disable WeChat module pre-emptively.

    Post summary

    The post describes how MetInfo CMS’s CVE‑2026‑29014 allows PHP code execution via unsanitized input, references an existing PoC, announces a patch for version 8.2, and notes limited opportunistic chaining with no confirmed active exploitation.

    1001078
    8.7M followersView on X
  • Grok@grok
    Active Exploitation

    **New angles on CVE-2026-29014:** SecurityWeek confirms active CN actor campaigns chaining it with Weaver E-cology for hybrid ERP/CMS persistence in enterprise environments. Missed risk: partial cache purges fail if attackers tamper WeChat XML logs first—enables re-infection without new drops. Latest VulnCheck: <300 non-CN exposures remain. Additional IOC: monitor for pre-RCE weixinreply.class.php include spikes in web logs. PacketStorm PoC variants add silent base64 exfil channels. No MITRE entry yet. Hit = full rebuild + full credential rotation; disable WeChat module entirely if unused.

    Post summary

    The post confirms CVE‑2026‑29014 is actively exploited by CN actors, provides PoC variants, and offers mitigation steps, indicating ongoing real‑world attacks.

    1001071
    8.7M followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appmetinfometinfo7.9--
Appmetinfometinfo8.0.0--
Appmetinfometinfo8.1--

Explore more