CVE-2026-78032

SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an attacker with the web server privilege.

  • Published Aug 28, 2026
  • CVSS 9.3 critical
  • 0.6% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-78032 at the National Vulnerability Database