CVE-2026-47212
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, Twili
CVSS
5.3
Medio
EPSS
0.3%
p19
KEV
—
Exploit Today
6
0-100
Publicado: 14 jul 2026 · Última mod.: 15 jul 2026 · CWE-306 · CWE-347
0.2%EPSS · 30 días0.3%
2026-08-042026-08-31
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, TwilioRequestParser::doParse() received the configured webhook secret but ignored the X-Twilio-Signature HMAC header, allowing unauthenticated POST requests to inject forged Twilio status payloads. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.
- github.comhttps://github.com/symfony/symfony/commit/8545fb2af6c07dfb5ef0fc8d9bccf86db2c94356
- github.comhttps://github.com/symfony/symfony/releases/tag/v6.4.40
- github.comhttps://github.com/symfony/symfony/releases/tag/v7.4.12
- github.comhttps://github.com/symfony/symfony/releases/tag/v8.0.12
- github.comhttps://github.com/symfony/symfony/security/advisories/GHSA-55rj-x2vc-4whq
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-844237.3 ALT—
———A vulnerability has been found in Casdoor up to 4.0.0. This affects an unknown function of the file controllers/resource.go of the component upload-resource API. Such manipulation leads to missing authentication. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor deleted the GitHub issue for this vulnerability without any explanation. Afterwards the vendor was contacted early about this disclosure via email but did not respond in any way.5hCVE-2026-796879.0 CRÍ—
———Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access.7hCVE-2026-187717.5 ALT—
———Missing authentication for critical function vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Authentication Bypass.
This issue affects Talassoft Industrial Management Software: from V4 before V.16.8hCVE-2026-12663——
———A security issue exists within ControlFLASH™, where the installer grants write permissions to the "Everyone" group on a product installation directory. This could allow arbitrary code execution, resulting in an attacker being given the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level.8hCVE-2026-829197.3 ALT—
———A vulnerability was identified in cu silicon up to 0.1.5. Affected by this vulnerability is the function create_app of the file views.py of the component edit Endpoint. Such manipulation leads to missing authentication. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.8hCVE-2026-829063.7 BAJ—
———A flaw has been found in sdcb chats up to 1.12.0. This impacts the function DownloadPublic of the file src/BE/web/Controllers/Chats/Files/FileController.cs of the component Signed File Download Endpoint. This manipulation causes missing authentication. Remote exploitation of the attack is possible. The attack's complexity is rated as high. The exploitability is said to be difficult. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.8h