05c12bb033
- CVE-2026-27174: Console eval RCE via missing exit after redirect - CVE-2026-27175: Command injection via rc/index.php + cycle_execs race condition - CVE-2026-27180: Supply chain RCE via update URL poisoning in saverestore module All three modules include documentation with Docker lab setup instructions.