go to Center block
Upper block

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

CAYIN Technology|CAYIN CMS-WS/CMS-SE/SMP - Arbitrary File Upload

TVN ID TVN-202608008
CVE ID CVE-2026-80233
CVSS 7.2 (High)
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected Products CMS-WS version 1.0.25336 and earlier
CMS-SE version 11.0.25336 and earlier
SMP version 4.0.25336 and earlier
Description CAYIN CMS-WS, CMS-SE, and SMP series products developed by CAYIN Technology have an Arbitrary File Upload vulnerability. Privileged remote attackers can upload and execute web shells backdoors, thereby enabling arbitrary code execution on the server.
Solution Update CMS-WS to version 1.0.26198 or later
Update CMS-SE to version 11.0.26198 or later
Update SMP to version 4.0.26198 or later
Credit Jing-Xun Sun
Public Date 2026-08-26
Top