IncidentMetInfo CMS Patch Ignored for 24 Days, Then Exploited
On May 1, 2026, attackers began exploiting CVE-2026-29014 , a PHP code injection vulnerability in MetInfo CMS with a CVSS score of 9.8. This flaw allows unauthenticated remote code execution, giving a














