CVE-2025-26900

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Feb 25, 2025
CWE ID 502

Summary

CVE-2025-26900 is a deserialization vulnerability affecting the Flexmls® IDX software from version n/a to 3.14.27. An attacker can exploit this issue by injecting untrusted data, resulting in object injection. This vulnerability could potentially be exploited to execute arbitrary code or gain unauthorized access to sensitive data, posing a significant risk to affected systems. Organizations using Flexmls® IDX are strongly advised to apply the necessary patches to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share