CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

[NEW] [critical] TYPO3 Extensions: Multiple Vulnerabilities

criticalCVE-2026-56092CVE-2026-56093CVE-2026-56094CVE-2026-56095CVE-2026-56096CVE-2026-77127
An attacker can exploit multiple vulnerabilities in various TYPO3 Extensions to execute arbitrary code, perform SQL injection, gain elevated privileges, manipulate data, disclose sensitive information, bypass security measures, or trigger a denial-of-service condition.

CSIRTS triage

What
Multiple vulnerabilities in various TYPO3 Extensions allow remote code execution, SQL injection, privilege escalation, data manipulation, information disclosure, security bypass, and denial-of-service attacks.
Who is affected
All deployments using affected TYPO3 Extensions without patch versions applied.
Urgency
Critical; unpatched extensions expose systems to immediate compromise including arbitrary code execution and data breach.
Action
Identify and update all affected TYPO3 Extensions to patched versions immediately; consult TYPO3 extension repository for CVE-specific remediation versions.

AI-assisted analysis generated from the source advisory — verify against the original.

Details

Source
CERT-Bund (BSI) Security Advisories (DE · national-cert · site)
Severity
critical
Published
2026-08-26
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3003

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-56092coverage & exploitation statusNVD · CVE.org
CVE-2026-56093coverage & exploitation statusNVD · CVE.org
CVE-2026-56094coverage & exploitation statusNVD · CVE.org
CVE-2026-56095coverage & exploitation statusNVD · CVE.org
CVE-2026-56096coverage & exploitation statusNVD · CVE.org
CVE-2026-77127coverage & exploitation statusNVD · CVE.org
CVE-2026-77128coverage & exploitation statusNVD · CVE.org
CVE-2026-77129coverage & exploitation statusNVD · CVE.org
CVE-2026-77130coverage & exploitation statusNVD · CVE.org
CVE-2026-77131coverage & exploitation statusNVD · CVE.org
CVE-2026-77133coverage & exploitation statusNVD · CVE.org
CVE-2026-77134coverage & exploitation statusNVD · CVE.org
CVE-2026-77135coverage & exploitation statusNVD · CVE.org
CVE-2026-77137coverage & exploitation statusNVD · CVE.org
CVE-2026-77139coverage & exploitation statusNVD · CVE.org
CVE-2026-77140coverage & exploitation statusNVD · CVE.org
CVE-2026-77141coverage & exploitation statusNVD · CVE.org
CVE-2026-77142coverage & exploitation statusNVD · CVE.org
CVE-2026-77146coverage & exploitation statusNVD · CVE.org
CVE-2026-77138coverage & exploitation statusNVD · CVE.org
CVE-2026-77136coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for TYPO3 Extensions

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from CERT-Bund (BSI) Security Advisories