Critical phpBB Flaw Lets Attackers Hijack Any Account with One Request

2026-06-09T14:52:14Z3abc09c91427724eb19924d3d65cc9570af5215e7122abe3fd240e2aeb533957
AI-securityCVE-2026-11645EDR-evasionNSOPoCRCEauthentication-bypassbackdoorcheck-pointchromeeverest-formsexploit-in-the-wildflowiseinstagrammetanpmpatchphpBBprompt-injection','UNK_DeadDrop','TA4922qilinred-hatspearphishingsupply-chainwhatsappwordpress

What happened

Multiple high-risk vulnerabilities and active exploit campaigns reported: a critical phpBB authentication-bypass allows account takeover with a single request; Google released a patch for CVE-2026-11645 (remote code execution in Chrome sandbox) exploited in the wild; Check Point’s Remote Access/Mobile Access suffers a critical auth bypass actively exploited by Qilin; Everest Forms Pro has an exploited RCE enabling rogue WordPress admin account creation; a 1-click Flowise RCE PoC can fully compromise self-hosted servers; Meta experienced an AI-related account recovery flaw exposing >20,000 IGs;

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
3abc09c91427724eb19924d3d65cc9570af5215e7122abe3fd240e2aeb533957
Enrichment time
2026-06-09T14:52:14Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Critical phpBB Flaw Lets Attackers Hijack Any Account with One Request · Baitaphish