CVE-2026-65552
Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.
CVSS
9.8
Critical
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Aug 6, 2026 · Last modified: Aug 6, 2026 · CWE-502
Not enough EPSS history yet.
Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-655819.8 CRI—
———Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.7hCVE-2026-655799.8 CRI—
———Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.6hCVE-2026-655789.8 CRI—
———Unauthenticated PHP Object Injection in Agora <= 1.9 versions.7hCVE-2026-655779.8 CRI—
———Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.7hCVE-2026-655769.8 CRI—
———Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.6hCVE-2026-655759.8 CRI—
———Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.7h