CVE-2026-12116
A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings, which can be change
CVSS
9.8
Critical
EPSS
0.4%
p30
KEV
—
Exploit Today
9
0-100
Published: Jul 9, 2026 · Last modified: Jul 9, 2026
0.4%EPSS · 30 days0.4%
2026-07-102026-07-21
A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings, which can be changed to a PHP interpreter, allowing an attacker to upload PHP data that will then be executed.
- github.comhttps://github.com/thexerteproject/xerteonlinetoolkits/commit/8ef20628f80bd88bd1fe3e5844a9116a910086b7
- github.comhttps://github.com/thexerteproject/xerteonlinetoolkits/issues/1543
- www.xerte.org.ukhttps://www.xerte.org.uk/index.php/en/news/blog/80-news/364-xerte-3-14-and-3-15-important-security-update
No related CVEs by CWE or product.