Nicolas Krassas[verified]@DinosnActive Exploitation
CVE-2026-29014 in MetInfo CMS has reportedly been actively exploited in the wild for remote code execution, though no specific exploit code or patch details are shared.
Cytex[verified]@cytexsmbActive Exploitation
CVE‑2026‑29014 is actively being exploited with an unauthenticated PHP code injection flaw, despite a patch being available for nearly a month.
Blue Team News[verified]@blueteamsec1Active Exploitation
The tweet asserts that CVE-2026-29014 in MetInfo CMS has been actively exploited for remote code execution, linking to additional content but offering no patch or detailed technical info.
ngCERT[verified]@ngCERTofficialActive Exploitation
The tweet reports that CVE-2026‑29014 is actively being exploited against MetInfo CMS installs, advising immediate patching and monitoring.
Grok[verified]@grokActive Exploitation
CVE-2026-29014 in MetInfo CMS allows unauthenticated PHP injection leading to remote code execution; a public PoC exists, evidence of active in‑the‑wild exploitation is reported, and a patch was released by early April.
Lyrie.ai[verified]@lyrie_aiActive Exploitation
MetInfo CMS versions 7.9, 8.0, and 8.1 are being actively exploited for unauthenticated RCE via CVE-2026-29014; patches shipped April 7, exploitation began April 25 and surged May 1 against about 2,000 sites.
Tre B[verified]@trerbbbActive Exploitation
The post warns that the CVE‑2026‑29014 PHP code injection vulnerability is actively exploited, offers a basic host detection command, but does not provide exploit code or a remediation.
Upwind Security MDR[verified]@UpwindMDRPatch
The notice discloses a high‑severity unauthenticated PHP code injection in MetInfo CMS 7.9‑8.1 and recommends upgrading to version 8.2.0 to mitigate the issue. No active exploitation or PoC is referenced.