PT-2026-26268 · Unknown · Themeton Zuut

CVE-2025-60233

·

Published

2026-03-19

·

Updated

2026-03-23

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Themeton Zuut versions through 1.4.2
Description The software contains a flaw due to deserialization of untrusted data, which can lead to object injection. This allows for potential remote code execution. The vulnerability exists in the way the software handles serialized data, potentially allowing an attacker to inject malicious objects.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-60233

Affected Products

Themeton Zuut