Two Remote Code Execution Vulnerabilities Disclosed in Content Management Systems
Article Content
Two critical vulnerabilities were disclosed on September 8, 2026, affecting content management systems. CVE-2026-86732, rated 8.7 (High), impacts Craft CMS versions before 5.10.12, allowing authenticated users to execute arbitrary PHP code via the element-index endpoint. Attackers can exploit this by injecting malicious classes through specific parameters. CVE-2026-54611, rated 5.5 (Medium), affects InstantCMS versions prior to 2.18.2, enabling remote authenticated attackers to upload malicious components that can execute PHP code through custom .htaccess files. Both vulnerabilities have been patched in their respective latest versions. Users are advised to update their systems immediately to mitigate potential risks.
Key Points: • CVE-2026-86732 allows RCE in Craft CMS for versions before 5.10.12. • CVE-2026-54611 affects InstantCMS versions prior to 2.18.2 with RCE potential. • Both vulnerabilities were published on September 8, 2026, and have patches available.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.