Sploitus New CVE Exploits Affect DedeCMS with Remote Code Execution Vulnerability
Article Content
- •CVE-2026-XXXX allows remote code execution in DedeCMS.
- •The vulnerability has a CVSS score of 7.2/8.8, indicating high severity.
- •Proof-of-concept scripts are available but are non-weaponized.
A newly discovered vulnerability in DedeCMS (CVE-2026-XXXX) allows for remote code execution through the 'dede/update_guide.php' script. The vulnerability has a CVSS score of 7.2/8.8 and was disclosed on September 25, 2026. The affected version is DedeCMS V5.7.118, and the advisory includes non-weaponized proof-of-concept scripts for educational purposes. This vulnerability is significant as it could potentially allow attackers to execute arbitrary code on affected systems. The advisory emphasizes that the proof-of-concept scripts are for authorized testing only, and misuse is not condoned. Current status indicates that the vulnerability is now public, and organizations using DedeCMS should take immediate action to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2021-44228 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
China-Linked QTFY Group Targets Critical Infrastructure with Advanced Exploits The Joint Cybersecurity Advisory JCSA-20260826-01, released on August 26, 2026, details ongoing activities by the China-linked hacking group QTFY, attributed to Nanjing Xinjiuwei Network Technology Co. Active since 2018, QTFY employs platforms like QScan and QTRouter to exploit vulnerabilities in critical…