MetInfo CMS Code Injection RCE Exploitation | MSSP Advisory

Critical
DateMay 5, 2026
📋Executive Summary
Threat actors are actively exploiting CVE-2026-29014, a critical code injection vulnerability in MetInfo CMS versions 7.9, 8.0, and 8.1 that allows unauthenticated remote code execution with a CVSS score of 9.8. The flaw permits attackers to execute arbitrary PHP code without authentication, giving them complete control over affected websites. VulnCheck reports active exploitation in the wild targeting this open-source content management system.
⚠️Why It Matters for MSSPs
Your clients running MetInfo CMS face immediate compromise with attackers gaining full server control to steal data, install backdoors, or pivot into internal networks. Any MSSP client using this relatively obscure CMS is sitting exposed right now, and if they get breached because you did not warn them about active exploitation, that becomes your retention and liability problem.
Recommended Action
Scan all client environments immediately for MetInfo CMS installations and either patch to the latest version or take affected sites offline within 24 hours.
🔒
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
Get your first advisory free →
🏷️Threat Category
Vulnerability Disclosure

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.