CRITICAL 9.8 CVE-2026-73389 Published 19 Aug 2026

Kalles Addons PHP Object Injection

Worried this affects one of your servers?

Unauthenticated PHP Object Injection in Kalles Addons versions <= 1.0.6.

An attacker can exploit this vulnerability to inject malicious PHP objects, leading to remote code execution.

  • Affected versions: <= 1.0.6
  • Impact: Remote code execution

Reference: CVE-2026-73389 on NVD

← Back to Security News