SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-12116

CRITICAL · CVSS 9.8 EPSS 0.57% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-09 · Last synced 2026-08-08

CyberRota Analysis

AI-Generated

A critical vulnerability in Xerte Online Tools enables remote code execution by allowing an attacker to modify the antivirus binary path in the server settings to point to a PHP interpreter. This misconfiguration permits the upload and execution of malicious PHP scripts, posing a significant risk to the integrity and security of the affected systems. Organizations using Xerte Online Tools should prioritize immediate remediation to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-12116
Severity
CRITICAL
CVSS
9.8
EPSS
0.57%

Original NVD Description

A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings, which can be changed to a PHP interpreter, allowing an attacker to upload PHP data that will then be executed.