CVE-2026-63227: Critical RCE Vulnerability in Koollab LMS (CVSS 9.9)


This text was generated using artificial intelligence (AI).On July 29, 2026, the Cyber Security Agency of Singapore (CSA) disclosed a critical vulnerability in the Koollab learning management system (LMS) from the vendor Three Learning. The vulnerability, identified as CVE-2026-63227 According to CSA Advisory AL-2026-094, this vulnerability has a CVSS score of 9.9 (Critical) is exploited, allowing attackers to take complete control of the affected server through remote code execution (RCE).

The affected version is 5.3.2 the software. A security update to version 5.4.0, which addresses the issue, was provided by the manufacturer.

Are my systems affected? Check now →