NPM · AUGUST 2026 · CONFIRMED

MaxSite CMS <= 109.5 Authentication Bypass & RCE Vulnerabilities

CVE-2026-70552Severity: CRITICAL

MaxSite CMS versions 109.5 and earlier contain critical vulnerabilities that enable unauthenticated remote code execution and admin access. Users of these versions are strongly advised to upgrade immediately.

What happened

MaxSite CMS versions 109.5 and earlier have been confirmed to contain multiple critical vulnerabilities (CVE-2026-70552, CVE-2026-70553, CVE-2026-70554) that allow unauthenticated attackers to execute arbitrary code and gain admin-level access. The vulnerabilities stem from issues in the AJAX dispatcher, application configuration, and cookie handling. Attackers can exploit these to manipulate poll states, inject malicious PHP code, and execute arbitrary commands as the web server user.

To assess your exposure, check if your MaxSite CMS installation is version 109.5 or earlier. If so, upgrade to version 109.6 or later immediately. Review server logs for any suspicious activity, particularly around the time these vulnerabilities were disclosed. Pay close attention to any unexpected changes in poll states or vote counts, as these may indicate exploitation.

For detailed technical information and CVSS scores, consult the primary sources linked in the threat data section. These vulnerabilities have been rated CRITICAL with a CVSS score of 9.8, indicating a severe risk to affected systems.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If maxsite cms is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats