Security Affairs
Pegasus Used Against MEP Investigating Pegasus, Citizen Lab Finds|JADEPUFFER: First End-to-End AI-Driven Ransomware Operation|The Anatomy of a Shadow AI Supply-Chain Breach: Lessons from the 2026 Vercel Incident|Law enforcememt operation disrupted Malicious Residential Proxy Networks NetNut|Government and Healthcare Are the Weakest Links in Global Email Security|Europe Confirms Record €4.1B Penalty Against Google for Android Practices|U.S. CISA adds a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalog|430,000 FortiGate Devices Exposed in FortiBleed Ransomware Link|Adobe fixed multiple maximum-severity flaws in ColdFusion and Campaign Classic|Alleged Scattered Spider Hacker Extradited to U.S. to Face Cybercrime Charges|Oracle E-Business Suite Flaw Under Active Attack, 950 Systems Exposed|Azure CLI Targeted in LSHIY Password Spray Campaign Across 64 Orgs|Pegasus Used Against MEP Investigating Pegasus, Citizen Lab Finds|JADEPUFFER: First End-to-End AI-Driven Ransomware Operation|The Anatomy of a Shadow AI Supply-Chain Breach: Lessons from the 2026 Vercel Incident|Law enforcememt operation disrupted Malicious Residential Proxy Networks NetNut|Government and Healthcare Are the Weakest Links in Global Email Security|Europe Confirms Record €4.1B Penalty Against Google for Android Practices|U.S. CISA adds a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalog|430,000 FortiGate Devices Exposed in FortiBleed Ransomware Link|Adobe fixed multiple maximum-severity flaws in ColdFusion and Campaign Classic|Alleged Scattered Spider Hacker Extradited to U.S. to Face Cybercrime Charges|Oracle E-Business Suite Flaw Under Active Attack, 950 Systems Exposed|Azure CLI Targeted in LSHIY Password Spray Campaign Across 64 Orgs|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

CVE-2016-10033 PHPMailer flaw leaves millions of websites vulnerable

A security expert discovered a critical vulnerability in the PHPMailer that leaves millions of websites vulnerable to remote exploit. A critical vulnerability, tracked as CVE-2016-10033, affects PHPMailer, one of the most popular open source PHP libraries used to send emails. It has been estimated that more than 9 Million users worldwide leverages on this library. Millions […]

CVE-2016-10033 PHPMailer flaw leaves millions of websites vulnerable

A security expert discovered a critical vulnerability in the PHPMailer that leaves millions of websites vulnerable to remote exploit.

A critical vulnerability, tracked as CVE-2016-10033, affects PHPMailer, one of the most popular open source PHP libraries used to send emails. It has been estimated that more than 9 Million users worldwide leverages on this library.

Millions of websites using PHP and popular CMS, including WordPress, Drupal, and Joomla currently use the library for sending emails.

The CVE-2016-10033 affects all versions of the library before the PHPMailer 5.2.18 release.

PHPMailer

The flaw was discovered by the notorious security expert Dawid Golunski from Legal Hackers, it could be exploited by a remote unauthenticated attacker to execute arbitrary code in the context of the web server and compromise the target web application.

“An independent research uncovered a critical vulnerability in PHPMailer that could potentially be used by (unauthenticated) remote attackers to achieve remote arbitrary code execution in the context of the web server user and remotely compromise the target web application.” Golunski explained in a security advisory.

“To exploit the vulnerability an attacker could target common website components such as contact/feedback forms, registration forms, password email resets and others that send out emails with the help of a vulnerable version of the PHPMailer class.” 

The advisory provides a few details about the exploitation of the flaw to give users a chance to fix their PHPMailer class. The experts confirmed that the details of the CVE-2016-10033 vulnerability will be published shortly.

Golunski reported the flaw to the developers who have promptly fixed it in the PHPMailer 5.2.18 release.
The researcher also plans to include in the advisory a proof-of-concept exploit code and video PoC of the attack.

Administrators and developers must update to the patched release as soon as possible.

Stay tuned

[adrotate banner=”9″]

Pierluigi Paganini

(Security Affairs – CVE-2016-10033, hacking)