PHPbb forums are now being hacked left and right.
All the details are here:
https://www.aikido.dev/blog/phpbb-authe ... bypass-rce
UPGRADE IMMEDIATELY
Re: UPGRADE IMMEDIATELY
Done. The phpBB developers should improve their communication, because they make it really hard to figure out if the "big issue" is related to OAuth or not. Initially I thought it's the case, and then all the noise would've been irrelevant, but on re-reading the main security issue fixed in 3.3.17 isn't connected to OAuth.