RCE flaw in ImunifyAV puts millions of Linux-hosted sites at risk
ID: a7156817-132d-5bf4-9b23-4c2fa1e5d07f
STIX ID: report--a7156817-132d-5bf4-9b23-4c2fa1e5d07f
Feed Name: Bleeping Computer
Threat Score
**ImunifyAV/Imunify360 RCE vulnerability:** A flaw in the AI-bolit deobfuscation logic (pre-32.7.4.0) lets attacker-controlled function names be executed (via call_user_func_array), enabling remote code execution when malicious PHP is scanned; a PoC exists, vendor fixes and backported updates are available, and the issue affects a widely deployed hosting scanner used across millions of websites.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
