CRITICAL 9.3 NVD
CVE-2026-77138
The extension fails to safely process untrusted client input of an attacker-controlled cookie directly to PHP's unserialize(). A remote, unauthenticated attacke
The extension fails to safely process untrusted client input of an attacker-controlled cookie directly to PHP's unserialize(). A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the TYPO3 server.
References
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-08-25 via NVD.
Risk Timeline
CVE Disclosed2026-08-25 · -1 days ago
Remediation Resources
Official Advisory
typo3.org/security/advisory/typo3-ext-sa-2026-014
vulnfeed aggregates 12116 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.