Threat actors are actively exploiting a critical security vulnerability in MetInfo, an open-source content management system, according to VulnCheck research. CVE-2026-29014 is a code injection flaw with a CVSS score of 9.8 that allows arbitrary code execution. The vulnerability affects MetInfo CMS versions 7.9, 8.0, and 8.1 and involves an unauthenticated PHP code issue.
