Known Exploited Vulnerability: CVE-2016-10033

PHPMailer Command Injection Vulnerability

Catalog version: 2026.06.09 Date added: 2025-07-07 Due date: 2025-07-28 CISA catalog

Vendor: PHP

Product: PHPMailer

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Known ransomware campaign use: Unknown

Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/PHPMailer/PHPMailer/releases/tag/v5.2.18 https://github.com/advisories/GHSA-5f37-gxvh-23v6 https://nvd.nist.gov/vuln/detail/CVE-2016-10033

CWEs

cvelogic Threat Intelligence