logo

Millions of sites at risk from Imunify360 critical flaw exploit

ID: 01a2ae10-e319-59ec-8906-a0a15cf8a715

STIX ID: report--01a2ae10-e319-59ec-8906-a0a15cf8a715

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2025-11-14

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

A critical remote code execution vulnerability in ImunifyAV/Imunify360 (before v32.7.4.0) allows attackers to upload specially crafted obfuscated PHP that the scanner's deobfuscator executes, enabling arbitrary PHP or system command execution and potential full server takeover; Patchstack published technical details and a PoC while CloudLinux fixed the issue on October 21, 2025, but active exploitation is unconfirmed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.