Threats·Cloud & SaaSBreakingYii2 Starter Kit Debug and Gii Module Exposure Allows Remote Arbitrary File Generation and RCE (CVE-2026-103475)A critical security flaw in yii2-starter-kit exposes the Gii code generator and debug modules to all remote IP addresses by default, allowing unauthenticated RCE.CST Newsroom1 Oct 20268 min read