VORANT. Threat Intelligence Sign in Get the full feed

TYPO3 CMS patches two confidentiality flaws

routine vulnerability technology

ANSSI advises TYPO3 CMS admins to patch two vulnerabilities allowing data confidentiality breach and security policy bypass.

ANSSI (CERT-FR) issued an advisory covering two vulnerabilities in TYPO3, an open-source content management system, affecting the cms-backend and cms-lowlevel components. The flaws allow an attacker to compromise data confidentiality and bypass security policy restrictions. Affected versions span multiple TYPO3 branches: 11.x prior to 11.5.54, 12.x prior to 12.4.49, 13.x prior to 13.4.35, 14.x prior to 14.3.7, cms-backend prior to 10.4.60, and cms-lowlevel prior to 14.3.7.

The issues are tracked as CVE-2026-77132 and CVE-2026-85400, with corresponding GitHub security advisories published by TYPO3 on 8 September 2026. No indication of active exploitation is provided in the advisory. Organizations running TYPO3 CMS should review the vendor's security bulletins and apply the corresponding patched versions as soon as possible to remediate the confidentiality and security-bypass risks.

Mentioned in this report

Vulnerabilities CVE-2026-77132CVE-2026-85400

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1131

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free