securityonline.info 8/25/2026, 1:30:59 PM · external

Critical RCE flaw in TYPO3 Powermail lets attackers hijack sites

Critical RCE flaw in TYPO3 Powermail lets attackers hijack sites
CyberSIXT Evidence Panel
Primary Source news.typo3.com
CISA KEV Not in KEV
Patch Patch Status Unknown

THE content discusses a critical security vulnerability (CVE-2026-77136) in TYPO3 Powermail that allows remote code execution (RCE) due to improper access control, currently being exploited by attackers. TYPO3 developers have issued a warning for users to update their systems immediately or risk total compromise. The vulnerability is triggered when an admin improperly configures a specific field, allowing attackers to execute arbitrary commands.

Additionally, another threat (CVE-2026-77138) involves insecure deserialization in the HTML5 Video Player extension, requiring immediate uninstallation. Affected versions include POWermail versions 10.9.2 and below, and 11.0.0 to 13.2.0. The recommended mitigation is to update to the latest versions. Uninstallation is advised for the HTML5 Video Player due to lack of a patch.

View Primary Source Via securityonline.info

Article by CyberSIXT