CRITICAL 9.8 CVE-2026-62120 Published 10 Oct 2026

Law Office PHP Object Injection Vulnerability

Worried this affects your website?

Law Office versions up to and including 3.20 are affected by an Unauthenticated PHP Object Injection vulnerability.

The flaw can be exploited without authentication, impacting all Law Office versions up to 3.20.

Reference: CVE-2026-62120 on NVD

← Back to Security News