Verified vulnerability record
CVE-2026-6433
Custom CSS JS PHP <= 2.0.7 - Unauthenticated SQL Injection to RCE
Custom CSS JS PHP <= 2.0.7 - Unauthenticated SQL Injection to RCE
Sensor telemetry
31 attempts · 10 sensors
First-party observations recorded across 13 attacker IPs.
Evidence
Active exploitation observed
Previdian independently recorded this as exploited after first seeing it in honeypot sensors.
Actionable artifact
Nuclei template available
Public scanner coverage helps validate exposed systems.
Evidence, telemetry, and action stay attached to the CVE.
Browse exploited vulnerabilities →