
CVE-2026-27990 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX ConFix confix allows PHP Local File … https://www.cve.org/CVERecord?id=CVE-2026-27990
Post summary
The post announces CVE-2026-27990, describing it as an improper control of filename for include/require that enables remote file inclusion in a PHP program, but it does not provide a PoC, exploit, or patch details.
