Ghostwire

CVE-2026-5965: NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to...

CRITICAL CVSS 9.8 EPSS 6.34%

Published: April 21, 2026 | Last Modified: April 21, 2026

Description

NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.

Ghostwire Analysis — What This Means Practically

Exploitation Probability (EPSS): Moderate — 6.34% (91th percentile)

Measurable exploitation probability. Should be patched in the normal vulnerability management cycle.

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References