logo

CVE-2026-77136: TYPO3 Powermail RCE Flaw Exploited in the Wild

ID: 3a54447b-ce05-5e28-a2e5-00790c13e42e

STIX ID: report--3a54447b-ce05-5e28-a2e5-00790c13e42e

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-08-25

Date Updated: 2026-08-25

Author: Do Son

...
...

TYPO3 maintainers patched a critical Powermail Server-Side Template Injection (CVE-2026-77136) that allows unauthenticated remote code execution and is reported to be actively exploited in the wild; they also warned of an unpatched PHP object injection in the deprecated HTML5 Video Player (CVE-2026-77138). Administrators are advised to update Powermail to the fixed versions or disable the vulnerable field and to uninstall the unsupported video-player extension immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.