CRITICAL
9.8 CVE-2026-66672 Published 20 Aug 2026
Flatastic PHP Object Injection
Worried this affects one of your servers?
Unauthenticated PHP Object Injection in Flatastic versions 2.0 and below.
Attackers can exploit this vulnerability to execute arbitrary PHP code, leading to remote code execution (RCE).
- Affects Flatastic versions 2.0 and below.
- No user interaction or authentication is required to exploit this vulnerability.
Reference: CVE-2026-66672 on NVD
← Back to Security News