June 23, 2026
- PoCs out for two web app RCE chains — CVE-2026-48909, a PHP object injection → RCE in SP LMS (CVSS 9.5), and CVE-2026-25860, a reflected XSS → OS command execution in OpenClinic GA's DICOM upload, both have public exploit code. SP LMS PoC · OpenClinic write-up · Vulnerabilities & Exploits