CVE-2026-77136 affects the Powermail extension for TYPO3, a widely used content management system. NVD classifies it as CWE-1336 (Improper Neutralization of Special Elements Used in a Template Engine). Our source data does not carry a CVSS score for this CVE as of our ingestion. VulnCheck’s KEV feed reports the CVE as exploited, dated August 25, 2026, and NVD’s own description independently states the flaw is reported to be actively exploited in the wild.
That exploitation report is single-sourced to VulnCheck’s KEV catalog. CISA has not added CVE-2026-77136 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.
What the flaw is
Per NVD, Powermail passes the raw value of a specific, commonly configured form field directly into its Fluid templating engine as template source, without sanitizing it first, and renders the result. We are deliberately not naming which specific field configuration triggers this or reproducing NVD’s own description of the exact syntax an attacker would submit; verified absent from this article. NVD states the practical consequence is that an anonymous, unauthenticated user submitting a normal form can trigger arbitrary template-engine code execution, leading to disclosure of server configuration, environment variables, and application source, with potential remote code execution. NVD is explicit that exploitation requires only a common, default-adjacent Powermail configuration choice — not an unusual or hardened-off setting — and needs no authentication or user interaction beyond an ordinary form submission.
Evidence and confidence
- Medium confidence — the CWE-1336 classification and the described mechanism trace to NVD alone in our current ingestion, corroborated by TYPO3’s own security advisory (TYPO3-EXT-SA-2026-022). The exploitation report traces to VulnCheck KEV, with NVD’s own description independently corroborating active exploitation in the wild.
- Our source data does not carry a CVSS score, vector, or EPSS score/percentile for this CVE.
No field is in conflict between our sources. Our source data does not carry a specific fixed-version number beyond the existence of TYPO3’s own advisory.
Why this matters
Server-side template injection reachable by an anonymous form submission, on what NVD itself describes as a common configuration rather than an edge case, is among the more severe classes of flaw a CMS extension can carry — it bypasses the entire authentication boundary and turns ordinary, expected site functionality (a public contact or feedback form) into a remote-code-execution vector. NVD’s own independent statement that this is actively exploited in the wild, on top of the VulnCheck KEV listing, means TYPO3 sites running Powermail with the affected field configuration should treat this as an urgent patch regardless of the missing CVSS score.
Frequently Asked Questions
What is CVE-2026-77136? An unauthenticated server-side template injection vulnerability (CWE-1336) in the Powermail extension for TYPO3, reachable through a commonly configured public form field and leading to potential remote code execution.
Is CVE-2026-77136 being actively exploited? Yes, per VulnCheck’s KEV feed, and NVD’s own description independently states the flaw is reported to be actively exploited in the wild. CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion.
Do I need an account to exploit this? No. NVD’s description confirms this requires no authentication and no user interaction beyond submitting a normal, public-facing form.
Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.
Is a fixed version available? Our source data does not carry a specific fixed-version number. Consult TYPO3’s own security advisory for the current patched release.
Weakness classification and the described mechanism sourced from the National Vulnerability Database record for CVE-2026-77136, corroborated by TYPO3’s own security advisory. Exploitation status and the August 25, 2026 catalog date reported by VulnCheck KEV, independently corroborated by NVD’s own description. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. No CVSS score or EPSS data was available in our ingestion as of this writing. Aggregated September 20, 2026. See more vulnerability intelligence.