MaxSite CMS through version 109.6 deserializes attacker-controlled session-cookie data with PHP unserialize() without restricting permitted classes. A hardcoded session-encryption key permits unauthenticated attackers to forge session cookies containing crafted serialized PHP objects. Deserialization can invoke magic methods on available application classes, causing object injection and potentially code execution when a usable gadget chain exists.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This six-file Python/PHP repository is an operational Joomla exploitation suite. CVE-2026-Joomla-Suite.py is the command-line entry point: it accepts one target or a target list, can fingerprint installed extensions, supports concurrent scanning, optional proxying and JSON output, and invokes the modules in joomla_exploits.py. It loads payloads/x7-panel.php and attempts the listed extension-specific CVE modules in sequence or a module selected with --cve. Successful deployments are logged locally in panels_joomla.txt and scan_joomla_live.log. The suite claims seven unauthenticated extension paths and includes an additional credential-dependent CVE-2026-73373/com_media path in code. The PHP payload is a functional web shell rather than a benign proof-of-concept: it exposes unauthenticated command execution, filesystem reconnaissance, and arbitrary file-writing/upload features. The only Python dependency is requests; winrarzips_brand.py provides presentation/banner code. CVE and affected-version claims are repository assertions; only the SP LMS Joomla <5.2.2 condition is explicitly stated in the supplied content.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated PHP object-injection/deserialization vulnerability in MaxSite CMS through version 109.6. A hardcoded encryption key permits forging ci_session cookies; their unrestricted deserialization can invoke gadget-chain magic methods, enabling application-state corruption and potentially remote code execution.
An unauthenticated PHP object-injection vulnerability in MaxSite CMS through version 109.6. A hardcoded session encryption key enables attackers to forge ci_session cookies, which are deserialized without class restrictions; this can corrupt application state and potentially result in code execution where suitable PHP gadget classes are present.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.