CERT Polska disclosed three vulnerabilities in OpenSolution Quick.CMS affecting versions through 6.8.0, warning that all versions should be treated as vulnerable even though testing was performed only on version 6.8. The issues were assigned CVE-2026-63301, CVE-2026-63302, and CVE-2026-63303. They include a client-side-only restriction bypass that allows an authenticated administrator to delete the primary language and trigger a denial of service, a local file inclusion flaw in admin.php via the p parameter, and a path traversal issue in URI handling that can expose files from a sibling directory of the webroot.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
OpenSolution assessed exploitation likelihood for all three disclosed Quick.CMS vulnerabilities as very low and decided fixes were not necessary. This vendor response was reported as part of the coordinated disclosure.
CERT Polska coordinated disclosure of three vulnerabilities affecting OpenSolution Quick.CMS versions through 6.8.0: CVE-2026-63301, CVE-2026-63302, and CVE-2026-63303. The disclosure noted only version 6.8 was tested, but all versions should be considered vulnerable.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecert.pl
Open sourcecwe.mitre.org
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.