PHP Object Injection is a vulnerability tracked across 3 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed February 21, 2026; most recent activity June 16, 2026.
A critical vulnerability, CVE-2026-45247, has been identified in the Mirasvit Full Page Cache Warmer for Magento 2, allowing unauthenticated remote code execution via a crafted CacheWarmer cookie. The flaw, rated 9.8 on…
A series of critical vulnerabilities (CVEs) have been disclosed affecting multiple products, all with a CVSS score of 9.8. CVE-2026-25775 allows unauthorized firmware operations on SenseLive X3050. CVE-2026-8935 enables…
CVE-2026-27206 identifies a vulnerability in the Zumba Json Serializer library, affecting versions 3.2.2 and below. The library's deserialization feature allows attackers to instantiate arbitrary PHP classes via…