CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on July 7, 2025, with organizations required to implement fixes by July 28, 2025. Organizations unable to implement available mitigations should consider discontinuing use of vulnerable PHPMailer implementations until proper security measures can be deployed. While CISA has not confirmed whether this vulnerability is being used in ransomware campaigns, the potential for such exploitation remains a significant concern given the widespread deployment of PHPMailer. Organizations using affected PHPMailer versions face immediate risks, particularly those with internet-facing applications that process user input through email functionality. The technical nature of this vulnerability makes it particularly dangerous as PHPMailer is widely integrated into content management systems, web applications, and enterprise software solutions. This security weakness allows attackers to inject malicious commands that execute within the application’s context, potentially leading to complete system compromise. CVE-2016-10033 in PHPMailer allows attackers to execute arbitrary code through command injection in the mail() function. The vulnerability is being exploited in live cyberattacks, risking system compromise and data breaches. Organizations must fix this by July 28, 2025, after CISA's July 7 warning.
This Cyber News was published on cybersecuritynews.com. Publication date: Tue, 08 Jul 2025 10:20:13 +0000