AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-65578

CRITICAL · CVSS 9.8 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Unauthenticated PHP Object Injection vulnerabilities in Agora versions up to 1.9 allow attackers to exploit the application by injecting malicious objects, potentially leading to remote code execution and full system compromise. Organizations using affected versions should prioritize immediate patching or mitigation strategies, as the critical severity rating indicates a high risk of exploitation. This vulnerability poses a significant threat to any systems running the specified software, particularly in environments where security controls are lax.

CVE
CVE-2026-65578
Severity
CRITICAL
CVSS
9.8
EPSS
0.31%

Original NVD Description

Unauthenticated PHP Object Injection in Agora <= 1.9 versions.