CVE-2026-24765: The CI/CD Trojan Horse: Inside PHPUnit’s Unsafe Deserialization
The CI/CD Trojan Horse: Inside PHPUnit’s Unsafe Deserialization Vulnerability ID: CVE-2026-24765 CVSS Score: 7.8 Published: 2026-01-27 A critical insecure deserialization vulnerability in PHPUnit’s PHPT test runner allows local attackers to achieve Remote Code Execution (RCE) by crafting malicious coverage files. This flaw is particularly dangerous in CI/CD environments, where it can be leveraged to compromise…