{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/cypht/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:cypht:cypht:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-71981"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Cypht (\u003c 2.12.2)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","php","rce"],"_cs_type":"advisory","_cs_vendors":["Cypht"],"content_html":"\u003cp\u003eCypht versions prior to 2.12.2 are vulnerable to a PHP object injection flaw. The vulnerability resides in the application's logout handler, specifically within the processing of the 'back_query' GET parameter. An authenticated attacker can supply a malicious, base64-encoded serialized PHP object graph. The application decodes and passes this input directly to the PHP unserialize() function without implementing an allow-list, signature verification, or proper type restrictions. This lack of validation allows attackers to trigger gadget-chain exploitation, resulting in remote code execution (RCE) with the privileges of the web server process. Defenders should prioritize patching affected Cypht instances to version 2.12.2 or later to mitigate this risk.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated attacker to execute arbitrary system commands on the underlying host, leading to full compromise of the web server, potential lateral movement within the network, and exfiltration of sensitive application data.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all Cypht instances to version 2.12.2 or later immediately to patch CVE-2026-71981.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous requests to the logout handler containing base64-encoded strings within the 'back_query' parameter.\u003c/li\u003e\n\u003cli\u003eImplement strict request validation for all parameters passed to deserialization functions within the environment.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-01T23:09:14Z","date_published":"2026-09-01T23:09:14Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cypht-rce/","summary":"Cypht versions before 2.12.2 contain a PHP object injection vulnerability in the logout handler, allowing authenticated attackers to achieve remote code execution via serialized payloads.","title":"PHP Object Injection in Cypht","url":"https://feed.craftedsignal.io/briefs/2026-09-cypht-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cypht","version":"https://jsonfeed.org/version/1.1"}