Three CVE records published on August 10 describe critical flaws in two lightweight administrative web tools.
The lead pair affects phpfm through version 1.8.0. [CVE-2026-72593](https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/72xxx/CVE-2026-72593.json) says an empty default `auth_pass` pe...