The CVE-2026-15686 vulnerability is an incorrect check of a function return value in the multi_query method of Adminer, allowing remote attackers to execute arbitrary code on affected installations. This requires authentication to exploit. Adminer users, administrators, and security teams should be aware of this vulnerability and take necessary actions to mitigate it. The vulnerability has a CVSS score of [truncated]
CVE-2021-21311 is a Server-Side Request Forgery (SSRF) vulnerability in Adminer. CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on 2025-09-29, which indicates known exploitation and a need for urgent remediation planning. Organizations that use Adminer should treat this as a high-priority exposure, especially if the service is reachable from untrusted networks.