CRITICAL
TREXOM
CVE published 2026-09-15
CVE-2026-89308
CVE-2026-89308 is a critical unauthenticated OS command injection vulnerability in the ping.php endpoint, allowing remote code execution. The CVE record was published on 2026-09-15T12:17:53.603Z and was last modified on 2026-09-18T19:24:36.593Z. The NVD entry is currently Deferred. Defenders, security teams, and system administrators responsible for systems potentially exposed to this vulnerability should [truncated]