PatchSiren cyber security CVE debrief
CVE-2026-77138 TYPO3 CVE debrief
A critical vulnerability, CVE-2026-77138, exists in an unnamed TYPO3 extension. This vulnerability allows remote code execution via PHP Object Injection when an attacker-controlled cookie is processed by PHP's unserialize(). The vulnerability is caused by the extension's failure to safely process untrusted client input of an attacker-controlled cookie directly to PHP's unserialize(). This could lead to significant impact, including unauthenticated attacks and potential system compromise. TYPO3 server administrators and defenders should assess exposure and prioritize patching or mitigation due to the critical severity and potential for remote code execution.
- Vendor
- TYPO3
- Product
- Extension "HTML5 Video Player vs. Powermail"
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-25
- Original CVE updated
- 2026-09-28
- Advisory published
- 2026-08-25
- Advisory updated
- 2026-09-28
Who should care
TYPO3 server administrators and defenders should assess exposure and prioritize patching or mitigation due to the critical severity and potential for remote code execution. This vulnerability can impact TYPO3 server security, and defenders should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Affected operator, platform, vulnerability-management, and security-team impact should be carefully
Why it matters
CVE-2026-77138 is a critical vulnerability in a TYPO3 extension that allows remote code execution via PHP Object Injection. Defenders should prioritize verifying exposure and applying patches or mitigations due to the high severity and potential for unauthenticated attacks.
- Remote code execution requires immediate patching or mitigation
- Unauthenticated attacks can occur without user interaction
- CVSS score of 9.3 indicates critical severity
Technical summary
The unnamed TYPO3 extension fails to safely process untrusted client input of an attacker-controlled cookie directly to PHP's unserialize(), allowing a remote, unauthenticated attacker to supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the TYPO3 server. This vulnerability has a CVSS score of 9.3, indicating critical severity. The vulnerability is caused by the lack of proper input validation and sanitization in the extension's code. Defenders should prioritize verifying exposure of TYPO3 servers using the affected extension and apply patches or mitigations as available.
Defensive priority
Defenders should prioritize verifying exposure of TYPO3 servers using the affected extension and apply patches or mitigations as available.
Recommended defensive actions
- Verify TYPO3 server exposure to the vulnerable extension
- Apply patches or mitigations as available
- Monitor for suspicious cookie-based attacks
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE and NVD records provide details on the vulnerability, its CVSS score of 9.3, and the affected systems. A reference to the TYPO3 security advisory is also available. The vulnerability is confirmed to exist in the unnamed TYPO3 extension, and defenders should verify exposure of TYPO3 servers using the affected extension. Evidence limits are based on available source information, and further verification is recommended.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-77138 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-77138
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-77138 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77138
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://typo3.org/security/advisory/typo3-ext-sa-2026-014
f4fb688c-4412-4426-b4b8-421ecf27b14a
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.