chiprook
← Security
SecurityOctober 4, 2026, 22:00

CVE-2026-100382: CVSS 10.0 RCE in MediaWiki External Data extension

A critical unauthenticated remote code execution flaw was found in MediaWiki's External Data extension, rated CVSS 10.0 and affecting all releases before 3.7. Exploitation is confirmed in the wild, a public PoC exists in Phabricator task T434961, and admins logged automated attempts within a day of the 25 September disclosure.

CVE-2026-100382: CVSS 10.0 RCE in MediaWiki External Data extension
#MediaWiki
Read next
Security

Cisco ISE CVE-2026-76460: CVSS 10.0 auth bypass exploited in the wild

Security

CVE-2026-75650 in Magento: 132,792 Matches and a 10.0 CVSS

Security

CVE-2026-69730: CVSS 9.8 RCE in Windows DNS Server in September Patch

Security

MaxKB's CVSS 10.0 CVE: Patch Fixed Shell Quoting, Not the Approval Gate