CVE-2026-77136Active Exploitation

MEDIUMCVSS 9.5 · CRITICAL

Exploitation ongoing with high activity in latest observed window (4 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

The extension passes the raw value of a form field configured as "This field contains the name of the sender" directly into a Fluid View as template source, without any sanitization, and renders it. An anonymous, unauthenticated user can submit Fluid template syntax in that field to execute arbitrary Fluid ViewHelpers leading to disclosure of server configuration, environment variables and application source, and potentially remote code execution. Exploitation requires only that a form field is configured as the sender_name field, a common and default-adjacent Powermail configuration. No authentication or user interaction beyond a normal form submission is required. This vulnerability is reported to be actively exploited in the wild.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1336

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-08-25: 4Active Exploitation · 2026-08-25: 2Patch / Workaround · 2026-08-25: 2Technical Details · 2026-08-25: 408-25
Signal classification2 categories
Active Exploitation
250.0%
Disclosure
250.0%
Referenced assets3 URLs
Full discourse4 posts
  • Daily CyberSecurity@Daily_CyberSec
    Active Exploitation

    A critical TYPO3 Powermail RCE flaw (CVE-2026-77136) is actively exploited in the wild. Update immediately to prevent server compromise and data leaks. #TYPO3 #Powermail #Vulnerability #CyberSecurity #CVE202677136 https://securityonline.info/cve-2026-77136-typo3-powermail-rce-flaw/

    Post summary

    The post reports a critical RCE vulnerability in TYPO3 Powermail (CVE‑2026‑77136) that is currently being exploited in the wild and urges immediate patching.

    060120724
    13.0K followersView on X
  • yousukezan@yousukezan
    Active Exploitation

    TYPO3の人気フォーム拡張Powermailに、認証なしで任意コマンド実行につながる重大な脆弱性「CVE-2026-77136」が見つかり、実際の攻撃で悪用されている。別途、非推奨のHTML5 Video PlayerにもRCEにつながる脆弱性が確認された。 CVE-2026-77136はSSTIで、「This field contains the name of the sender」を有効にした環境が影響する。入力値がFluid Viewへ渡され、テンプレート構文を送信すると任意のViewHelperを実行できる。影響するPowermailは10.9.2以下、11.0.0~12.6.0、13.0.0~13.2.0で、10.9.3、12.6.1、13.2.1で修正された。 CVE-2026-77138はHTML5 Video Player 0.2.1以下に存在し、Cookie値をunserialize()で処理することでPHP Object InjectionからRCEにつながる。保守されておらず修正版はなく、開発者は削除を案内している。 https://securityonline.info/cve-2026-77136-typo3-powermail-rce-flaw/

    Post summary

    CVE-2026-77136 in TYPO3 Powermail is actively exploited and patches are available, while CVE-2026-77138 affecting an HTML5 Video Player is confirmed but unpatched.

    000131.5K
    14.9K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-77136 The extension passes the raw value of a form field configured as "This field contains the name of the sender" directly into a Fluid View as template source, without a… https://www.cve.org/CVERecord?id=CVE-2026-77136 ----- Traducción: CVE-2026-77136 La … https://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑77136, describing how an extension improperly passes raw form input into a Fluid View template, but it provides no PoC, exploit code, or patch details.

    0000038
    102 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-77136 The extension passes the raw value of a form field configured as "This field contains the name of the sender" directly into a Fluid View as template source, without a… https://www.cve.org/CVERecord?id=CVE-2026-77136

    Post summary

    A new vulnerability (CVE‑2026‑77136) has been identified in an extension that passes raw form field values into a Fluid View template source, potentially allowing code injection; no exploit, PoC, patch, or active exploitation has been reported.

    00000813
    58.0K followersView on X

Explore more