ThreatCluster

Two Remote Code Execution Vulnerabilities Disclosed in Content Management Systems

First seen 9 Sep 2026, 15:15 UTC Osv.Dev 57

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities were disclosed on September 8, 2026, affecting content management systems. CVE-2026-86732, rated 8.7 (High), impacts Craft CMS versions before 5.10.12, allowing authenticated users to execute arbitrary PHP code via the element-index endpoint. Attackers can exploit this by injecting malicious classes through specific parameters. CVE-2026-54611, rated 5.5 (Medium), affects InstantCMS versions prior to 2.18.2, enabling remote authenticated attackers to upload malicious components that can execute PHP code through custom .htaccess files. Both vulnerabilities have been patched in their respective latest versions. Users are advised to update their systems immediately to mitigate potential risks.

Key Points: • CVE-2026-86732 allows RCE in Craft CMS for versions before 5.10.12. • CVE-2026-54611 affects InstantCMS versions prior to 2.18.2 with RCE potential. • Both vulnerabilities were published on September 8, 2026, and have patches available.

Ask AI about this cluster

Timeline

2026-09-08
CVE-2026-54611 published
Remote Code Execution vulnerability disclosed in InstantCMS affecting versions before 2.18.2.
Osv.Dev
2026-09-08
CVE-2026-86732 published
Remote Code Execution vulnerability disclosed in Craft CMS affecting versions before 5.10.12.
Osv.Dev
Recent
Patches released
Craft CMS and InstantCMS released updates to address the vulnerabilities; users are urged to upgrade.
Osv.Dev