CVE-2026-27206 is a vulnerability tracked across 1 threat cluster and 2 intelligence report mentions on ThreatCluster. First observed February 21, 2026; most recent activity February 22, 2026.
CVE-2026-27206 identifies a vulnerability in the Zumba Json Serializer library, affecting versions 3.2.2 and below. The library's deserialization feature allows attackers to instantiate arbitrary PHP classes via…