Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
High

Quick.CMS insecure deserialization RCE

IdentifiersCVE-2026-11860CWE-502· Deserialization of Untrusted Data

CVE-2026-11860 is a deserialization of untrusted data vulnerability in OpenSolution Quick.CMS. The application deserializes user-controlled serialized data received over plaintext HTTP without ensuring integrity or authenticity, and without sufficient validation or class restrictions. Because the serialized payload can be modified in transit, an attacker positioned to tamper with the HTTP traffic can inject malicious objects into the deserialization process. Crafted payloads can invoke dangerous PHP magic methods such as __wakeup() and __destruct() and leverage available gadget chains, ultimately resulting in arbitrary code execution on the server. Exploitation is triggered when an administrator accesses the admin panel.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows arbitrary code execution on the Quick.CMS server. An attacker able to tamper with the serialized data in transit can cause malicious object instantiation and execution of gadget chains during deserialization, leading to full compromise of the application context and potentially the underlying host, depending on the privileges of the web server process.

Mitigation

If you can’t patch tonight, do this now.

Enforce HTTPS-only communication for all affected Quick.CMS administrative and application traffic, especially any path carrying serialized data to the admin panel. Remove plaintext HTTP exposure, prevent downgrade or mixed-content scenarios, and prioritize patching affected installations. Until patched, reduce exposure to attacker-controlled networks and monitor for suspicious admin-panel-triggered deserialization behavior.

Remediation

Patch, then assume compromise.

Upgrade Quick.CMS to a patched release and ensure the vendor patch published on 2026-05-14 for version 6.8 is applied. The patch mitigates the issue by limiting the affected communication path to HTTPS, preventing in-transit tampering of serialized payloads. Unpatched deployments remain vulnerable.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity4

Community discussion across Reddit, Mastodon, and other social sources.