Skip to content
New CVE Exploits Affect DedeCMS with Remote Code Execution Vulnerability

New CVE Exploits Affect DedeCMS with Remote Code Execution Vulnerability

First seen 25 Sep 2026, 06:26 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 25, 2026 at 10:54 UTC
  • •CVE-2026-XXXX allows remote code execution in DedeCMS.
  • •The vulnerability has a CVSS score of 7.2/8.8, indicating high severity.
  • •Proof-of-concept scripts are available but are non-weaponized.

A newly discovered vulnerability in DedeCMS (CVE-2026-XXXX) allows for remote code execution through the 'dede/update_guide.php' script. The vulnerability has a CVSS score of 7.2/8.8 and was disclosed on September 25, 2026. The affected version is DedeCMS V5.7.118, and the advisory includes non-weaponized proof-of-concept scripts for educational purposes. This vulnerability is significant as it could potentially allow attackers to execute arbitrary code on affected systems. The advisory emphasizes that the proof-of-concept scripts are for authorized testing only, and misuse is not condoned. Current status indicates that the vulnerability is now public, and organizations using DedeCMS should take immediate action to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2021-12-10
CVE-2021-44228 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-03-14
CVE-2023-23397 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-04-12
CVE-2024-3400 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-25
CVE-2026-XXXX disclosed
DedeCMS vulnerability allows remote code execution through 'dede/update_guide.php'.
Sploitus

More articles in this cluster (2)

Following this threat?

Track CVE-2021-44228 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed