CRITICAL 9.8 CVE-2026-73993 Published 20 Aug 2026

FundEngine PHP Object Injection

Worried this affects one of your servers?

FundEngine, a PHP-based e-commerce platform, is affected by an unauthenticated PHP Object Injection vulnerability in versions up to 1.7.9.

Exploiting this issue could allow an attacker to inject malicious PHP objects, leading to remote code execution.

Reference: CVE-2026-73993 on NVD

← Back to Security News