CVE-2026-32563
Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
CVSS
9.8
Critical
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Aug 24, 2026 · Last modified: Aug 25, 2026 · CWE-502
Not enough EPSS history yet.
Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-782659.8 CRI—
——0Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.13hCVE-2026-782629.8 CRI—
——0Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.1dCVE-2026-408778.7 HIG—
——0Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.1dCVE-2026-768437.8 HIG—
——0The official Flair wheels for 0.15.0 and 0.15.1 still contain flair/models/clustering.py, whose ClusteringModel.load static method returns pickle.loads(joblib.load(str(model_file))) and so executes arbitrary Python while loading a model file. Loading a model supplied by an attacker therefore runs that attacker's code with the privileges of the loading process. This is the same sink and the same file as CVE-2024-10073, which records 0.15.0 as the fixed version on the basis that clustering support was dropped in that release; the module was removed from the documented API but remains present in the distributed artifact and reachable by importing flair.models.clustering directly, so the earlier record's fixed version does not hold for the shipped package.1dCVE-2026-666509.8 CRI—
——0Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.1dCVE-2026-781477.3 HIG35.8%
——11A vulnerability was found in ggml-org llama.cpp bec4772f6. The impacted element is the function deserialize_tensor of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component ggml-RPC Server. Performing a manipulation of the argument op/op_params results in deserialization. The attack may be initiated remotely. This vulnerability is distinct from CVE-2026-34159 (GHSA-j8rj-fmpv-wcxw, PR #20908), which only added a buffer==nullptr rejection in create_node() and does not validate op or op_params. The reported GitHub issue was closed automatically due to inactivity.1d