CVE-2026-94503: Px-Lab Zombify

Critical severity, CVSS 10.0. EPSS: 0.3% chance of exploitation in the next 30 days.

Unrestricted Upload of File with Dangerous Type vulnerability in PX-lab Zombify zombify allows Upload a Web Shell to a Web Server.This issue affects Zombify: from n/a through 1.7.7.

Affected products

  • Px-Lab Zombify: up to and including 1.7.7

Published 2026-10-09. Last modified 2026-10-09.