CVE-2026-12116: Xerte Online Tools
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings, which can be changed to a PHP interpreter, allowing an attacker to upload PHP data that will then be executed.
Affected products
- Xerte Xerte Online Tools: before v3.15.5 (fixed in v3.15.5); before 3.14.6 (fixed in 3.14.6)
Published 2026-07-09. Last modified 2026-07-09.