CVE-2026-84834
Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.
CVSS
9.8
Crítico
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 3 sept 2026 · Última mod.: 3 sept 2026 · CWE-502
Sin historial EPSS suficiente todavía.
Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-197956.2 MED—
———IBM Qiskit SDK 2.1.0 through 2.5.1 could allow a local attacker to cause a denial of service due to improper handling of a specially crafted object during deserialization. A malicious QPY payload can trigger a segmentation fault, causing the application to crash when deserializing untrusted input.16hCVE-2026-847539.8 CRÍ—
———Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.19hCVE-2026-847528.8 ALT—
———Contributor PHP Object Injection in RTMKit <= 2.1.5 versions.18hCVE-2026-84832——
———SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API token can execute arbitrary commands with "nobody" privileges.18hCVE-2026-846708.8 ALT—
——0Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that can be instantiated when deserializing cached performance reports stored in the build directory on the Jenkins controller, allowing attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller.19hCVE-2026-846508.8 ALT—
——0In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to specify the values of transient fields that will be deserialized, the impact depending on how those fields are used.19h