CVE-2026-42569Disclosure

MEDIUMCVSS 9.4 · CRITICAL

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

phpVMS is a PHP application to run and simulate an airline. Prior to version 7.0.6, a critical vulnerability in phpVMS allowed unauthenticated access to a legacy import feature. This issue has been patched in version 7.0.6.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-306CWE-862

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

RISING

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 11 mentions across 6 observed days
  • Momentum state: rising

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 8 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 3 mentions (2026-05-11); latest day: 3
  • 11 total mentions across 6 days

Deep dive

Activity timeline11 mentions / 6d
01223Mentions · 2026-05-05: 1Mentions · 2026-05-09: 2Mentions · 2026-05-10: 1Mentions · 2026-05-11: 3Mentions · 2026-05-12: 1Mentions · 2026-06-18: 3Active Exploitation · 2026-05-11: 1Patch / Workaround · 2026-05-11: 2Technical Details · 2026-05-05: 1Technical Details · 2026-05-09: 2Technical Details · 2026-05-10: 1Technical Details · 2026-05-11: 2Technical Details · 2026-05-12: 105-0505-0905-1005-1105-1206-18
Signal classification3 categories
Disclosure
872.7%
General
218.2%
Active Exploitation
19.1%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-05-051
Disclosure1
2026-05-092
Disclosure2
2026-05-101
Disclosure1
2026-05-113
Active Exploitation1Disclosure1General1
2026-05-121
Disclosure1
2026-06-183
Disclosure2General1
Full discourse11 posts
  • FOFA@fofabot
    Disclosure

    ⚠️⚠️ CVE-2026-42569 (CVSS 9.4): Unauthenticated access to legacy import feature before v7.0.6 — patch phpVMS airline/VMS deployments. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJwaHBWTVMi 🎯611 phpVMS-tagged surfaces indexed on https://en.fofa.info (FOFA proxy for virtual-airline stacks; verify before claiming vuln density). FOFA Query: app="phpVMS" 🔖Refer: https://github.com/nabeelio/phpvms/releases #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    A newly disclosed high‑severity vulnerability (CVE‑2026‑42569) affects phpVMS versions before 7.0.6, allowing unauthenticated access to a legacy import feature; a patch is available and FOFA data indicates 611 indexed surfaces.

    0802782.6K
    14.4K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    [1] TheHackerWire — CVE-2026-42569 Analysis: One Line of Code Left Behind: CVE-2026-42569 Turns phpVMS Airline Systems Into Wipe Targets

    Post summary

    The brief headline mentions a CVE affecting phpVMS airline systems but offers no technical details, PoC, exploit, or patch information; additional investigation is needed.

    1000042
    294 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    On May 9, 2026, researchers disclosed CVE-2026-42569, a critical vulnerability in phpVMS, a PHP-based airline simulation application used for flight operations tracking and pilot management. The flaw is deceptively simple: a deprecated "legacy importer" feature was left…

    Post summary

    The text announces the discovery of CVE-2026-42569 in phpVMS, describing it as a critical flaw involving a legacy importer feature, but provides no further technical details, PoC, or patch information.

    1000039
    294 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    One Line of Code Left Behind: CVE-2026-42569 Turns phpVMS Airline Systems Into Wipe Targets. On May 9, 2026, researchers disclosed CVE-2026-42569, a critical vulnerability in phpVMS, a PHP-based airline simulation application used for flight operations tracking and pilot…

    Post summary

    Researchers disclosed a critical vulnerability in phpVMS, but no further technical details, PoC, exploit availability, patch, or evidence of exploitation are provided.

    1000046
    294 followersView on X
  • Vignesh_Pravin@VigneshVic23698
    Disclosure

    CVE-2026-42569: phpVMS Flaw Lets Hackers Wipe Full Database https://thecybrdef.com/cve-2026-42569-phpvms-database-deletion-vulnerability/ #CVE202642569 #Cyberupdate #Cybersecuirty

    Post summary

    The article announces CVE‑2026‑42569, a phpVMS flaw that permits wiping the entire database; no details on exploitation, patch, or PoC are provided.

    0000034
    2 followersView on X
  • Harishraam@unknownmatter19
    General

    CVE-2026-42569: phpVMS Flaw Lets Hackers Wipe Full Database https://thecybrdef.com/cve-2026-42569-phpvms-database-deletion-vulnerability/ #CVE202642569 #Cyberupdate #Cybersecuirty

    Post summary

    The tweet announces a phpVMS vulnerability (CVE‑2026‑42569) that could enable a full database wipe, but it offers no evidence of exploitation, PoC code, or mitigation information.

    0000033
  • NerdieNews@NewsNerdie
    Active Exploitation

    ⚠️ CVE-2026-42569 in phpVMS is being exploited to bypass authorization and wipe databases entirely. Patch immediately to prevent data loss. For sysadmins: how long until you can realistically patch this across all environments? #NerdieNews #CyberSecurity #InfoSec #Vulnerability https://t.co/mh5UHuGjRc

    Post summary

    The tweet reports that CVE-2026-42569 in phpVMS is actively exploited to bypass authentication and destroy databases, and urges immediate patching.

    0000029
    63 followersView on X
  • selva@SelvaKtm2
    Disclosure

    CVE-2026-42569: phpVMS Flaw Lets Hackers Wipe Full Database https://thecybrdef.com/cve-2026-42569-phpvms-database-deletion-vulnerability/ #CVE202642569 #Cyberupdate #Cybersecuirty https://t.co/tHMOYwcQJj

    Post summary

    The tweet announces CVE-2026-42569, a flaw in phpVMS that can allow attackers to wipe the entire database, without detailing patches, exploitation status, or a PoC.

    0000034
    5 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42569 Unauthenticated Access to Legacy Import Feature in phpVMS Before ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42569 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet references CVE-2026-42569, noting an unauthenticated access flaw in phpVMS, but provides no evidence of PoC, exploitation, or mitigation steps.

    0000049
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2026-42569 phpVMS is a PHP application to run and simulate an airline. Prior to version 7.0.6, a critical vulnerability in phpVMS … CVSS 9.4 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-42569 #HP #CyberSecurity #InfoSec

    Post summary

    The tweet announces CVE‑2026‑42569 as a critical vulnerability in phpVMS with a CVSS of 9.4, notes that no patch is available, and links to a detailed analysis.

    0000055
    90 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 phpVMS, Unauthenticated Access to Legacy Import Feature, #CVE-2026-42569 (Critical) https://dailycve.com/phpvms-unauthenticated-access-to-legacy-import-feature-cve-2026-42569-critical/

    Post summary

    The tweet announces CVE-2026-42569, a critical unauthenticated access flaw in phpVMS's legacy import feature, and points to a detailed report.

    0000035
    191 followersView on X

Explore more