Back to search

CVE-2026-5965

CRITICAL
9.8NVD

NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.

CVSS v3.1 Score

9.8
/ 10.0
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Information

Published
21 avr. 2026
Updated
21 avr. 2026
Status
Awaiting Analysis
Source
twcert@cert.org.tw

Weaknesses (CWE)

CWE-78

Similar CVEs

Other vulnerabilities of type CWE-78

Loading…

Monitor your products

Get automatic alerts for every new CVE affecting your equipment.

Enable monitoring