CVE-2026-12116
Xerte Xerte Online Tools
A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings, which can be changed to a PHP interpreter, allowing an attacker to upload PHP data that will then be executed.
- CVSS
- 9.8
- EPSS
- 0.57% 43.8% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.09