Skip to main content
Mallory
Back to stories
actively-exploited-vulnerabilityinternet-facing-service-vulnerabilityrapid-weaponizationopen-source-dependency-vulnerability

Critical MetInfo CMS RCE Flaw Hit by Active Exploitation

Updated 11d agoFirst seen May 5, 20262 sources

Threat actors are actively exploiting CVE-2026-29014, a critical CVSS 9.8 vulnerability in the open-source MetInfo CMS that allows unauthenticated remote code execution through PHP code injection. The flaw affects MetInfo versions 7.9, 8.0, and 8.1 and stems from insufficient sanitization in Weixin/WeChat API requests handled by weixinreply.class.php, located under /app/system/weixin/include/class/. Successful exploitation can let attackers execute arbitrary code and potentially take full control of vulnerable servers.

MetInfo issued patches on April 7, 2026, but exploitation was observed by April 25 against honeypots in the United States and Singapore, before surging on May 1 with attacks concentrated on China and Hong Kong. Exploitation depends on the presence of the /cache/weixin/ directory, which is commonly created when the WeChat plugin is installed. Researchers said roughly 2,000 MetInfo CMS instances were reachable online, with the majority exposed in China.

Share:
Critical MetInfo CMS RCE Flaw Hit by Active Exploitation
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the earliest known activity through the most recent confirmed update.

4 EVENTS
Apr 7, 20261mo ago

MetInfo releases patches for CVE-2026-29014

MetInfo released fixes for CVE-2026-29014, a critical unauthenticated PHP code injection flaw in MetInfo CMS affecting versions 7.9, 8.0, and 8.1. The vulnerability can enable remote code execution via crafted requests to the weixinreply.class.php component when the WeChat-related cache directory is present.

Apr 25, 202623d ago

Exploitation of CVE-2026-29014 begins against honeypots

VulnCheck observed active exploitation of CVE-2026-29014 starting by April 25, with initial attacks targeting honeypots in the United States and Singapore. The activity showed threat actors were abusing the flaw in the wild shortly after patches became available.

May 1, 202617d ago

MetInfo CMS attacks surge and shift toward China and Hong Kong

On May 1, exploitation activity increased sharply, with attacks concentrating on targets associated with China and Hong Kong IP addresses. Reporting also noted that roughly 2,000 MetInfo CMS instances were exposed online, most of them in China.

May 5, 202613d ago

Researchers publicly report active exploitation of CVE-2026-29014

By early May 2026, VulnCheck and media reports disclosed that CVE-2026-29014 was being actively exploited in the wild. The reporting identified the bug as a critical CVSS 9.8 remote code execution issue in the MetInfo CMS Weixin/WeChat functionality.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

7 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.