CVE-2026-100382: CVSS 10.0 RCE in MediaWiki External Data extension
A critical unauthenticated remote code execution flaw was found in MediaWiki's External Data extension, rated CVSS 10.0 and affecting all releases before 3.7. Exploitation is confirmed in the wild, a public PoC exists in Phabricator task T434961, and admins logged automated attempts within a day of the 25 September disclosure.
- All External Data releases before 3.7 are affected; fix is upgrading to 3.7 or disabling the extension
- CVSS v4 10.0: unauthenticated RCE via unfiltered parser-function commands
- ZoomEye returned 1128 assets mentioning ExternalData in responses
- Attackers drop web shells named Nx_*.php in skins and upload directories
Read next
Security