CVE 9.3 CRITICAL

NewSoft|NewSoftOA – OS Command Injection_CVE-2026-5965

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.

AI Analysis

OS Command Injection vulnerability in NewSoftOA, allowing unauthenticated local attackers to inject arbitrary OS commands

Basic Information

ID CVE-2026-5965
Source twcert
Published Apr 21, 2026 at 03:32

Affected Product

Vendor NewSoft
Product NewSoftOA
Affected Versions NewSoft NewSoftOA 0

CWE Classification

AI Assessment

AI Score 9.3 / 10
AI Severity Critical
Vendor NewSoft
Product NewSoftOA

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.