MaxSite CMS — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
March 1, 2026
Last Seen
July 9, 2026

MaxSite CMS is a technology platform tracked across 2 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed March 1, 2026; most recent activity July 9, 2026.

Related Threat Clusters

  • ACSC Issues Critical Alert on Exploited CMS Vulnerabilities

    The Australian Cyber Security Centre (ACSC) has issued a second alert in two months regarding a large-scale hacking campaign exploiting unpatched vulnerabilities in content management systems (CMS). The campaign targets…

    10 articles · Updated July 9, 2026
  • CVE-2026-3395: Code Injection Vulnerability in MaxSite CMS

    A code injection vulnerability has been identified in MaxSite CMS versions up to 109.1, affecting the MarkItUp Preview AJAX Endpoint. This flaw allows remote attackers to execute arbitrary code via manipulated input…

    2 articles · Updated March 2, 2026

Recent Intelligence Reports

  • Second alert from ACSC in two months shows unpatched CMS bugs still exploited — Itnews.Au · July 9, 2026
  • CVE-2026-3395: Code Injection in MaxSite CMS — Radar.Offseq · March 2, 2026
  • Submit #762169: maxsite CMS CMS 109.1 Code Injection — Vuldb · March 1, 2026

CVSS v3.1 Breakdown