Cypht versions before 2.12.2 deserialize attacker-controlled data in the logout handler. The back_query GET parameter accepts a Base64-encoded serialized PHP object graph that is decoded and passed to unserialize() without an allow-list, signature validation, or object-type restriction. An authenticated attacker can exploit an available PHP gadget chain to execute arbitrary operating-system commands in the web-server process context.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This three-file Python proof of concept targets the reported Cypht CVE-2026-71981 insecure-deserialization vulnerability in versions earlier than 2.12.2. poc.py is the sole executable entry point; README.md documents setup and usage, while requirements.txt lists requests and beautifulsoup4. The script accepts a target IP address, valid username/password, and arbitrary shell command. It invokes a locally installed phpggc utility to generate and base64-encode a Monolog/rce9 serialized object chain that calls system(). It first fetches the Cypht root page, parses hm_page_key, submits an authenticated login request, then sends the generated payload in back_query to the logout endpoint. It reports any content appended after the normal HTML closing tags as command output, with an option to print the entire response. No hardcoded external IP addresses or domains are present; all network traffic targets the operator-provided HTTP host.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authenticated PHP object-injection flaw in Cypht versions before 2.12.2. A crafted, base64-encoded serialized PHP object graph supplied in the logout handler's back_query GET parameter reaches unserialize() without validation or restrictions, potentially enabling gadget-chain remote command execution as the web-server process.
An authenticated remote code execution vulnerability in Cypht versions before 2.12.2. A base64-encoded serialized object supplied through the logout handler's back_query parameter is decoded and passed to PHP unserialize() without restrictions, permitting gadget-chain exploitation as the web-server process.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.