CRITICAL 9.8 CVE-2026-62103 Published 11 Sept 2026

Everest Forms PHP Object Injection

Worried this affects one of your servers?

Unauthenticated PHP Object Injection found in Everest Forms plugin versions 3.6.0 and earlier.

An attacker could exploit this vulnerability to inject malicious PHP objects, leading to remote code execution.

Reference: CVE-2026-62103 on NVD

← Back to Security News