June 26, 2026
- CVE-2026-38526 (CVSS 9.9) — Krayin CRM RCE via the TinyMCE upload endpoint (
/admin/tinymce/upload) to drop a PHP webshell; PoC published. PoC · Vulnerabilities & Exploits
in Malware Weaponizes Prompt Injection to Sabotage AI Analysis as Gamaredon Retools Against Ukraine