CVE-2026-27206: RCE Vulnerability in Zumba Json Serializer Affects PHP Applications
First seen 22 Feb 2026, 06:09 UTC
•
•70% similarity
•48.1
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
CVE-2026-27206 identifies a vulnerability in the Zumba Json Serializer library, affecting versions 3.2.2 and below. The library's deserialization feature allows attackers to instantiate arbitrary PHP classes via untrusted JSON input, leading to potential remote code execution (RCE). Applications utilizing this library are at risk if they process attacker-controlled JSON data.
ThreatCluster AI
Timeline
2026-02-21
CVE-2026-27206 published
2026-02-21
Dev.To article published
2026-02-22
Radar.Offseq article published