CVE-2026-25544: Critical Payload CMS SQLi (CVSS 9.8) Exposes Admin Tokens Vulnerability Report CVE-2026-25544: Critical Payload CMS SQLi (CVSS 9.8) Exposes Admin Tokens Ddos February 10, 2026 0 A massive security hole has been blown open in Payload, the popular “Next.js native CMS” designed to... Read More Read more about CVE-2026-25544: Critical Payload CMS SQLi (CVSS 9.8) Exposes Admin Tokens