Content Blocks: Q4/2025 Milestones and Q1/2026 Goals
The Content Types Team wrapped up the major milestone of TYPO3 v14 support and focused on the long-awaited Content Blocks GUI.
Read moreCommunity Budget Report: A PHP Firewall for TYPO3
Sascha Egerer provides an update on his Community Budget Idea to add a PHP-based firewall to TYPO3, helping site owners block common attacks even when they can’t rely on server-level security.
TYPO3 Contribution in Numbers: January 2026
See the full recap of TYPO3’s January core contributions with 53 contributors, 163 reviews, bug fixes, features, and a big thank-you to our developers.
TYPO3-EXT-SA-2026-004: Vulnerability in bundled package in extension "Amazon AWS SDK" (aws)
It has been discovered that the extension "Amazon AWS SDK" (aws) bundles a vulnerable version of “aws/aws-sdk-php“ which is susceptible to use of a Broken or Risky Cryptographic Algorithm.
TYPO3-EXT-SA-2026-003: Vulnerability in bundled package in extension "Amazon Web Services (AWS) Toolbox" (aws_tools)
It has been discovered that the extension "Amazon Web Services (AWS) Toolbox" (aws_tools) bundles a vulnerable version of “aws/aws-sdk-php“ which is susceptible to use of a Broken or Risky Cryptographic Algorithm.
TYPO3-EXT-SA-2026-002: Vulnerability in bundled package in extension "AWS SDK for PHP" (aws_sdk_php)
It has been discovered that the extension "AWS SDK for PHP" (aws_sdk_php) bundles a vulnerable version of “aws/aws-sdk-php“ which is susceptible to use of a Broken or Risky Cryptographic Algorithm.
TYPO3-EXT-SA-2026-001: Insecure Deserialization in extension "Mailqueue" (mailqueue)
It has been discovered that the extension "Mailqueue" (mailqueue) is vulnerable to insecure deserialization.
AI Integration in TYPO3 Via MCP: The End of Backend Fumbling
Content management meets artificial intelligence — and takes a quantum leap. With the Model Context Protocol (MCP) extension for TYPO3, editors control their content directly from ChatGPT & Co. No more copy-paste, no more backend hopping. Simply write, edit, publish — all in one tool.
TYPO3-CORE-SA-2026-004: Insecure Deserialization via Mailer File Spool
It has been discovered that TYPO3 CMS is vulnerable to insecure deserialization.
TYPO3-CORE-SA-2026-003: Broken Access Control in Recycler Module
It has been discovered that TYPO3 CMS is susceptible to broken access control.