CRITICAL
9.8 CVE-2026-73389 Published 19 Aug 2026
Kalles Addons PHP Object Injection
Worried this affects one of your servers?
Unauthenticated PHP Object Injection in Kalles Addons versions <= 1.0.6.
An attacker can exploit this vulnerability to inject malicious PHP objects, leading to remote code execution.
- Affected versions: <= 1.0.6
- Impact: Remote code execution
Reference: CVE-2026-73389 on NVD
← Back to Security News