Tracked as CVE-2026-63077, the critical bug can be exploited without authentication for remote code execution.