Three CVE records published on August 10 describe critical flaws in two lightweight administrative web tools.
The lead pair affects phpfm through version 1.8.0. [CVE-2026-72593](https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/72xxx/CVE-2026-72593.json) says an empty default `auth_pass` permits an unauthenticated remote user to perform broad filesystem operations. [CVE-2026-72592](https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/72xxx/CVE-2026-72592.json) says an empty upload-extension filter permits a PHP webshell to be uploaded and executed. The assigning CNA rated both CVSS 9.8 and identifies versions through 1.8.0 as affected.
The [phpfm repository](https://github.com/dulldusk/phpfm) documents the tool's ability to create, edit, execute, upload, move, and delete files. It also states that password protection is optional and warns that the default permits anyone to access the script.
The third record, [CVE-2026-72590](https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/72xxx/CVE-2026-72590.json), affects crontab-ui through version 0.4.2. It describes URL-encoded newline injection in an `env_vars` parameter sent to `/crontab`, allowing arbitrary cron entries and command execution. The CNA also rated this issue CVSS 9.8. The [project repository](https://github.com/alseambusher/crontab-ui) documents optional basic authentication and deployment patterns that can make the management interface reachable beyond its default loopback binding.
Why it matters
Administrative web tools concentrate powerful functions behind a small interface. A file manager with no effective authentication can expose the same files and secrets available to its web process. If uploaded PHP executes, that file access can become remote code execution. A cron management interface that accepts injected entries can create persistent, repeated command execution under the service's privileges.
Exposure is not uniform. Network binding, reverse proxies, container port publishing, authentication, filesystem permissions, PHP handler configuration, service-account privilege, and mounted host paths can each increase or reduce practical impact. A critical score is a prioritization signal; it is not proof that a particular environment is compromised.
What defenders should do now
Start with discovery. Search web roots, container images, deployment manifests, process lists, and administrative hosts for phpfm and crontab-ui. Confirm the version, network binding, proxy route, authentication layer, service identity, upload destinations, executable-content policy, and mounted cron paths.
Remove direct internet reachability. Disable or remove the tools until a documented fixed release or effective compensating control is verified. If continued operation is necessary, bind the service to a dedicated management interface, enforce strong authentication at a trusted upstream boundary, apply network allowlists, and run it with the least filesystem and operating-system privilege possible.
For any phpfm instance that may have been reachable, review web and upload logs, unexpected or recently changed PHP files, child processes, persistence mechanisms, and outbound connections. For crontab-ui, compare active crontabs and cron spool files against known-good state; inspect application data, backups, reverse-proxy records, and command-execution telemetry for unexpected `env_vars` requests or scheduled jobs.
If evidence of unauthorized use appears, isolate the affected host, preserve evidence, scope accessible files and credentials, rotate exposed secrets, and recover from trusted artifacts.
What remains uncertain
The vulnerability descriptions and CVSS scores come from the assigning CNA's CVE records. The reviewed sources do not provide independent exploit reproduction or corroborated victim reporting. Project documentation supports the relevant product capabilities and configuration behavior, but does not independently prove each vulnerability claim.
No reviewed source establishes active exploitation, internet exposure counts, affected-install prevalence, confirmed impact, or a fixed release. The CVE records identify affected versions through phpfm 1.8.0 and crontab-ui 0.4.2. Teams should verify maintainer guidance and their own deployed state rather than infer that repository content or downstream packages have identical exposure.
Sources
- [CVE-2026-72592 — CVE Program record](https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/72xxx/CVE-2026-72592.json)
- [CVE-2026-72593 — CVE Program record](https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/72xxx/CVE-2026-72593.json)
- [phpfm project repository](https://github.com/dulldusk/phpfm)
- [CVE-2026-72590 — CVE Program record](https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/72xxx/CVE-2026-72590.json)
- [crontab-ui project repository](https://github.com/alseambusher/crontab-ui)