go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

NewSoft|NewSoftOA - OS Command Injection

TVN ID TVN-202604008
CVE ID CVE-2026-5965
CVSS 9.8 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products NewSoftOA version before 10.1.8.3
Description NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.
Solution Update to version 10.1.8.3 or later.
Credit Ting-Wei Hsieh (CHT Security)
Public Date 2026-04-21
Top