A vulnerability identified as CVE-2026-77136, affecting the TYPO3 Powermail extension, was reportedly exploited on the same day it was publicly disclosed, August 25, 2026. This rapid exploitation window was noted by a commercial security research firm, VulnCheck, which added the CVE to its Known Exploited Vulnerabilities (KEV) catalog on the disclosure date. The Computer Incident Response Center Luxembourg (CIRCL) also mirrored this listing, though it is considered an aggregator and not an independent corroborating source.
The vulnerability's exploitability was measured from its CVE publication date to its first appearance in a KEV catalog, indicating immediate weaponization. While the U.S. federal CISA KEV and the European Union's ENISA KEV catalogs do not list this particular CVE, the claim of same-day exploitation rests on the single commercial listing.
Public reports of exploitation also emerged on August 25, 2026, with two such reports collected from VulnCheck and CIRCL, each linking to original sources. These reports have not been independently verified by all security outlets.
The TYPO3 Powermail extension is a popular form builder for the TYPO3 content management system. Details regarding the specific nature of the vulnerability, its CVSS score, or weakness enumeration were not immediately available, though its EPSS score was noted as 0.55%, placing it in the 44.2th percentile. The rapid exploitation highlights the challenge organizations face in patching vulnerabilities immediately upon disclosure.






