HIGH Published Oct 6, 2026 CVE-2026-104747 CVE-2026-104747 published: Unauthenticated PHP Object Injection in Haaken <= 1.5 versions. View full NVD advisory → Related reading How CVE Scoring Works: Understanding CVSS Severity Ratings ← Back to CVE watch