PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-65579 axiomthemes CVE debrief

CVE-2026-65579 involves an unauthenticated PHP Object Injection vulnerability in the Agricola theme, version <= 1.21.0. This critical vulnerability, with a CVSS score of 9.8, allows for arbitrary code execution without authentication, potentially leading to complete system compromise. Affected users should prioritize patching or mitigating this vulnerability as soon as possible. The CVE record was published on 2026-08-06T15:17:19.560Z and has not been modified since then. The vulnerability has been reported and verified through the source item, but the full scope of affected systems and potential impact is still being assessed.

Vendor
axiomthemes
Product
Agricola
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-06
Original CVE updated
2026-08-06
Advisory published
2026-08-06
Advisory updated
2026-08-06

Who should care

Users of Agricola theme version <= 1.21.0, administrators of affected systems, security teams, and vulnerability management teams should be aware of this critical vulnerability. They should prioritize patching or mitigating this vulnerability as soon as possible to prevent potential exploitation. Additionally, operators of platforms hosting Agricola theme installations, as well as security teams and vulnerability management teams, should also be aware of this vulnerability and take necessary actions to protect their systems.

Technical summary

The Agricola theme version <= 1.21.0 is vulnerable to an unauthenticated PHP Object Injection attack. This type of vulnerability allows attackers to execute arbitrary PHP code without authentication, potentially leading to complete system compromise. The vulnerability has a CVSS score of 9.8, indicating critical severity. Users of the Agricola theme should prioritize patching or mitigating this vulnerability as soon as possible.

Defensive priority

Critical vulnerability in Agricola theme, unauthenticated PHP object injection, high CVSS score of 9.8.

Recommended defensive actions

  • Inventory and verify Agricola theme version
  • Apply patch or update to fixed version
  • Monitor for suspicious activity
  • Consider compensating controls
  • Review system logs for potential exploitation attempts

Evidence notes

Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The vulnerability has been reported and verified through the source item. However, the full scope of affected systems and potential impact is still being assessed. Defenders should verify Agricola theme versions and review system logs for suspicious activity. Evidence is limited to CVE and NVD details.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T15:17:19.560Z and has not been modified since then.