CVE-2016-15044Exploit

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A remote code execution vulnerability exists in Kaltura versions prior to 11.1.0-2 due to unsafe deserialization of user-controlled data within the keditorservices module. An unauthenticated remote attacker can exploit this issue by sending a specially crafted serialized PHP object in the kdata GET parameter to the redirectWidgetCmd endpoint. Successful exploitation leads to execution of arbitrary PHP code in the context of the web server process.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC and exploit tooling are both present
  • 1 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-07: 1PoC Mentioned / Linked · 2026-04-07: 1Exploit Tool / Code · 2026-04-07: 1Technical Details · 2026-04-07: 104-07
Signal classification1 categories
Exploit
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • 0day Signal@0dayPublishing
    Exploit

    🚨 CVE-2016-15044: Kaltura < 11.1.0-2 PHP Object In... Unauthenticated PHP object injection via GET param hits Kaltura's keditorservices - Metasploit module ready, 9.3 CVSS g... https://zerodaysignal.com/vulnerability/CVE-2016-15044 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE‑2016‑15044 allows unauthenticated PHP object injection in Kaltura <11.1.0‑2; a Metasploit module is ready, signalling exploit readiness.

    0000039
    204 followersView on X

Explore more