TopVuln

High-risk vulnerability digests

CVE-2026-5965

  • CRITICAL

Details

CVSS v3
9.8
CVSS v4
9.3
NVD published
2026-04-21 04:16:13
EPSS
8.7% probability · 92.5th percentile — 2026-05-12
Affected versions
NewSoft office automation (NewSoftOA) software
Summary
This is a critical unauthenticated OS command injection vulnerability in NewSoftOA, a popular office automation platform used by many organizations. The flaw allows unauthenticated local attackers to inject arbitrary OS commands that execute with elevated privileges on the affected server. Successful exploitation results in full, unrestricted compromise of the target server.
Remediation
Organizations running NewSoftOA should actively monitor for the release of an official security patch from the vendor. Restrict public and untrusted network access to NewSoftOA management interfaces until a patch can be applied. Apply the patch immediately once it becomes available.
Exploit info
No public exploit found yet.

View on NVD

TopVuln sends digest emails with high-risk CVE picks across multiple authoritative sources—curated with EPSS and AI. Choose daily per-stream emails and optional weekly or monthly roundups.

Subscribe — free email digest or paid plan

Information is aggregated from multiple authoritative sources for convenience; verify with NVD and vendors before operational decisions.