Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026042310040303 | Publication Time | 2026/04/23 10:22 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026/04/23 10:22 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】NewSoft International | NewSoftOA - OS Command Injection |
|||
| [Content] Forwarded from TWCERTCC-200-202604-00000025 【NewSoft International | NewSoftOA - OS Command Injection】(CVE-2026-5965, CVSS: 9.8) NewSoftOA, developed by NewSoft International, contains an OS Command Injection vulnerability. An unauthenticated local attacker may inject arbitrary operating system commands and execute them on the server. (Information Sharing Level: WHITE (Information content can be publicly disclosed) |
|||
| [Affected Platform]
NewSoftOA versions earlier than 10.1.8.3 |
|||
| [Recommended Actions]
Update to version 10.1.8.3 or later. |
|||
| [Reference] 1. https://www.twcert.org.tw/tw/cp-132-10856-4979f-1.html |
|||