AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-65572

CRITICAL · CVSS 9.8 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability allows for unauthenticated PHP Object Injection in A.Williams versions up to 1.3.1, potentially enabling attackers to execute arbitrary code or manipulate application behavior. Organizations using this software should prioritize immediate patching or mitigation strategies due to the critical severity rating and the potential for severe exploitation. All users of the affected versions are strongly advised to assess their exposure and take action promptly.

CVE
CVE-2026-65572
Severity
CRITICAL
CVSS
9.8
EPSS
0.31%

Original NVD Description

Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.