CRITICAL 9.8 CVE-2026-66672 Published 20 Aug 2026

Flatastic PHP Object Injection

Worried this affects one of your servers?

Unauthenticated PHP Object Injection in Flatastic versions 2.0 and below.

Attackers can exploit this vulnerability to execute arbitrary PHP code, leading to remote code execution (RCE).

  • Affects Flatastic versions 2.0 and below.
  • No user interaction or authentication is required to exploit this vulnerability.

Reference: CVE-2026-66672 on NVD

← Back to Security News