A critical flaw in the open-source DotNetNuke CMS, tracked as CVE-2026-40321, allows attackers to turn a malicious SVG upload into full server compromise by hijacking an administrator’s authenticated browser session. The attack begins when an attacker uploads an SVG file containing JavaScript and persuades a privileged user to open it; the script then runs in that user’s session and abuses trusted access inside the application. Reports say the issue affects a platform used by more than 750,000 websites and can lead to command execution, malware deployment, data theft, and disruption of security tools on the underlying Windows server.
The compromise chain uses DotNetNuke’s authenticated file-write functionality, including the /API/personaBar/ConfigConsole/UpdateConfigFile endpoint, to write an ASPX web shell or other backdoor to disk. Because the technique relies on legitimate SVG files, native browser execution, standard HTTP traffic, and authenticated requests, common controls such as antivirus, firewalls, and malware-removal tools may not reliably detect or block it. An official patch is available, and defenders are being urged to prioritize updates, restrict or disable unnecessary SVG and anonymous uploads, and review user registration settings that could expose the attack path.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
An official patch was made available for the DotNetNuke vulnerability, with defenders advised to prioritize patching, restrict or disable unnecessary SVG and anonymous uploads, and review user registration policies. Reports noted the issue could affect more than 750,000 websites using the platform.
A cross-site scripting vulnerability in DotNetNuke CMS, tracked as CVE-2026-40321, was reported as allowing attackers to upload a malicious SVG that executes in a privileged user's browser session. The flaw can be chained with an authenticated file-write endpoint to place an ASPX web shell on the server and achieve full server compromise.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcetechradar.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.