CVE-2026-12116: exploitation status and patch state
CVE-2026-12116 · CVSS 9.8 CRITICAL · EPSS 1%
A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings, which can be changed to a PHP interpreter, allowing an attacker to upload PHP data that will then be executed.
Is CVE-2026-12116 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at 1%.
Public exploit code: none found in monitored sources.