Mercusys Router Vulnerability Confirmed
Concrete CMS versions below 9.5.2 are vulnerable to PHP Object Injection via unserialize() calls. This vulnerability allows for potential crisis alert keyword injection.
Topics
Developing
- 884d Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore.
- 884d Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.
- 884d Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est.
- 884d Sed ut perspiciatis unde omnis iste natus error sit voluptatem accusantium doloremque laudantium.
Sources · 7 independent
Mastodon
“Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls.”
Bluesky Social
“CVE-2026-36607 - High (8.8) Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows unauthenticated brute-forc...”
Unlock the full story
Get a Pro subscription or above to see the live story progression and the full list of independent sources confirming each event as they happen.
Log in to upgrade