CVE-2026-12116Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings, which can be changed to a PHP interpreter, allowing an attacker to upload PHP data that will then be executed.

0.0/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-07-09: 3Technical Details · 2026-07-09: 307-09
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
By indicator
Full discourse3 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 HIGH - Xerte Online Tools tools server config RCE via antivirus binary path (CVE-2026-12116) Xerte Online Tools is vulnerable to remote code execution due to an unsafe “antivirus binary path” setting in the tools server configuration component. The root cause is improper input validation and insecure configuration handling that allows an executable path to be repointed to an interpreter. An attacker who can modify this configuration can set the antivirus path to a PHP interpreter and then upload PHP content that gets executed through the scanning workflow. Successful exploitation results in arbitrary code execution on the Xerte server, enabling full system compromise, data theft, and lateral movement. 👉 Affected: Xerte Online Tools (versions not specified; assume all deployments using tools server config) | Upgrade to No fix yet — treat as suspicious

    Post summary

    The post announces that Xerte Online Tools suffers from an RCE vulnerability caused by an unsafe antivirus binary path setting, with no patch available yet.

    00010148
    246 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-12116 A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings, which can be changed to a PHP interpreter, al… https://www.cve.org/CVERecord?id=CVE-2026-12116

    Post summary

    The passage announces an RCE vulnerability (CVE-2026-12116) in Xerte Online Tools that can be triggered by modifying the antivirus binary path to a PHP interpreter.

    00001749
    57.8K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-12116 A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings, which can be changed to a PHP interpreter, al… https://www.cve.org/CVERecord?id=CVE-2026-12116 ----- Traducción: CVE-2026-12116 Una… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑12116, a RCE vulnerability in Xerte Online Tools that lets attackers change the antivirus binary path to a PHP interpreter; it provides technical details but no exploit code, mitigation or evidence of active exploitation.

    0000043
    91 followersView on X

Explore more