SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-73364

CRITICAL · CVSS 9.8 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability affects Flexible Subscriptions versions up to and including 1.8.1, allowing for PHP Object Injection, which can lead to remote code execution. This critical flaw poses a significant risk to any systems utilizing the affected versions, potentially compromising sensitive data and system integrity. Organizations using Flexible Subscriptions should prioritize immediate updates to mitigate this severe threat.

CVE
CVE-2026-73364
Severity
CRITICAL
CVSS
9.8
EPSS
0.31%

Original NVD Description

Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.