Multiples vulnérabilités dans Typo3 (08 septembre 2026)
Multiple vulnerabilities have been discovered in Typo3, allowing attackers to compromise data confidentiality and bypass security policies. These vulnerabilities affect older versions of the CMS, requiring immediate patching to mitigate the risk.
Multiple vulnerabilities have been identified within the Typo3 Content Management System. These weaknesses could enable an attacker to gain unauthorized access to sensitive data and circumvent existing security measures. The vulnerabilities are present in several versions of Typo3.
Systems affected include Typo3/cms-backend versions prior to 11.5.54, Typo3/cms-backend versions prior to 12.4.49, Typo3/cms-backend versions prior to 13.4.35, Typo3/cms-backend versions prior to 14.3.7, and Typo3/cms-backend versions prior to 10.4.60, as well as Typo3/cms-lowlevel versions prior to 14.3.7.
A specific CVE identifier is CVE-2026-77132. Further details are available via the Typo3 security advisory: https://github.com/TYPO3/typo3/security/advisories/GHSA-8jw7-8qw5-gqr3 and https://github.com/TYPO3/typo3/security/advisories/GHSA-x5pg-547h-6r2p.
Users are advised to consult the Typo3 security advisory for information on how to apply the necessary patches and updates. The advisory provides links to the relevant security information and instructions.