CVE-2026-57149Disclosure

LOW

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: High priority (within 72h)

2.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-09-23)
  • 5 total mentions across 4 days

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-07-01: 1Mentions · 2026-07-03: 1Mentions · 2026-07-07: 1Mentions · 2026-09-23: 2Exploit Tool / Code · 2026-07-07: 1Patch / Workaround · 2026-07-03: 1Technical Details · 2026-07-01: 1Technical Details · 2026-07-03: 107-0107-0307-0709-23
Signal classification2 categories
Disclosure
266.7%
Exploit
133.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-07-011
Disclosure1
2026-07-031
Disclosure1
2026-07-071
Exploit1
Full discourse5 posts
  • FOFA@fofabot
    Disclosure

    ⚠️⚠️ CVE-2026-57149 (CVSS 9.9) + CVE-2026-55247 (CVSS 9.1) + CVE-2026-55248 (CVSS 9.1): Plone patch bundle — Classic portlet TALES injection to RCE (auth + portlet mgmt required) plus http://plone.app.event DoS/SSRF/XSS issues. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJQbG9uZSI= 🎯17.7K+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="Plone" 🔖Refer: https://securityonline.info/plone-rce-vulnerability/ #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    The post announces three high‑severity Plone CVEs, details their technical aspects (RCE, DoS, SSRF, XSS), provides FOFA search references, and indicates a patch bundle is available, but does not supply PoC code or evidence of active exploitation.

    0802525.3K
    14.7K followersView on X
  • Daily CyberSecurity@the_yellow_fall
    Disclosure

    A critical Plone RCE vulnerability (CVE-2026-57149, CVSS 9.9) allows TALES injection via the Classic portlet. Two more flaws enable DoS and SSRF. #Plone #RCE #CyberSecurity #CMS #PatchNow https://securityonline.info/plone-rce-vulnerability https://t.co/PFHFQJ0I8u

    Post summary

    The tweet announces a critical Plone RCE (CVE‑2026‑57149) with a CVSS of 9.9, noting additional DoS and SSRF flaws, but contains no PoC, exploit code, or active exploitation evidence.

    01081657
    12.9K followersView on X
  • YogSotho@YogSoth0
    Exploit

    #CVE-2026-57149 - Pl0neShell v3.0 - #Plone Exploit Kit Affected versions Plone 7.0.0,7.0.1 Plone >=6.0.0,<=6.0.3 Plone >=5.0.0,<=5.0.7 Features + Proper multithreaded scanning + Steganography payload delivery + Web UI for C2 management + 7 persistence methods (cron, systemd, bashrc, SSH, LD_PRELOAD, rc.local, at jobs) + Windows support (scheduled tasks, PowerShell reverse shell) + SOCKS5 proxy support + Built-in keylogger + Screenshot capture (experimental) + Remote file download/execute + Session management + Encrypted exfil channel #0days #hacking #security #cybernews #cybersecurity #RCE #antisec #infosec

    Post summary

    The tweet announces the Pl0neShell v3.0 exploit kit targeting CVE‑2026‑57149 on Plone, detailing the kit’s capabilities but providing no code links, evidence of active exploitation, or mitigation information.

    01020319
    1.9K followersView on X
  • Upwind Security MDR@UpwindMDR

    🚨Critical - Plone Classic Portlet TALES Expression Injection RCE (CVE-2026-57149) http://plone.app.portlets Classic portlet builds a TALES path expression from user-controlled template/macro fields and evaluates it as a full TALES expression. An authenticated user who can add/edit a Classic portlet can inject crafted TALES to execute code in the Plone process. 👉Affected: http://plone.app.portlets (Classic portlet) Versions: >=5.0.0,<5.0.8, >=6.0.0,<6.0.4, >=7.0.0,<7.0.2. Patch to 5.0.8 / 6.0.4 / 7.0.2

    0001069
    310 followersView on X
  • DailyCVE@dailycve

    🔴 Plone, Remote Code Execution, #CVE-2026-57149 (Critical) -DC-Sep2026-2533 https://dailycve.com/plone-remote-code-execution-cve-2026-57149-critical-dc-sep2026-2533/

    0000039
    238 followersView on X

Explore more