AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T11:17:32.490Z and has not been modified since then. CVE-2026-72593 is a critical vulnerability in phpfm version 1.8.0, allowing an unauthenticated remote attacker to access full file manager functionality, including reading, writing, deleting, and uploading files anywhere on the server filesystem [truncated]
The CVE-2026-72592 unrestricted file upload vulnerability affects dulldusk/phpfm through version 1.8.0, allowing unauthenticated remote attackers to execute arbitrary PHP code. The vulnerability is caused by an empty upload extension filter and no authentication enabled by default. Administrators and users of the affected product should be aware of this vulnerability and take immediate action to remediate [truncated]