CVE-2026-78032
SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an attacker with the web server privilege.
- Published Aug 28, 2026
- CVSS 9.3 critical
- 0.6% chance of exploitation in the next 30 days (EPSS)