Skip to content
Vulnerability intelligence

CVE-2026-49763 — Security Advisory

CVE-2026-49763: unauthenticated PHP Object Injection in the CF7-HubSpot bridge. Neither vendor caught it.

CVSS 9.8 2026