go to Center block
Upper block

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Openfind|SecuShare Pro - OS Command Injection

TVN ID TVN-202610001
CVE ID CVE-2026-107459
CVSS 9.3 (Critical) CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
9.8 (Critical) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products SecuShare Pro v4
Description The SecuShare Pro developed by Openfind has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server.
Solution Cloud edition: All MailCloud (including EaaS) environments have been fully updated. The service is not affected and no further action is required.
Standard edition: SecuShare Pro customers should contact the Openfind technical service team for assistance with the update.
Customized edition: Please verify the current system version and provide the version number to Openfind, who will provide the corresponding security patch.
Credit Openfind
Public Date 2026-10-08
Top