THE content discusses a critical security vulnerability (CVE-2026-77136) in TYPO3 Powermail that allows remote code execution (RCE) due to improper access control, currently being exploited by attackers. TYPO3 developers have issued a warning for users to update their systems immediately or risk total compromise. The vulnerability is triggered when an admin improperly configures a specific field, allowing attackers to execute arbitrary commands.
Additionally, another threat (CVE-2026-77138) involves insecure deserialization in the HTML5 Video Player extension, requiring immediate uninstallation. Affected versions include POWermail versions 10.9.2 and below, and 11.0.0 to 13.2.0. The recommended mitigation is to update to the latest versions. Uninstallation is advised for the HTML5 Video Player due to lack of a patch.