OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-15027

HIGH · CVSS 8.8 EPSS 3.16%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

CGServiSign by Changing is vulnerable to an OS Command Injection flaw that allows unauthenticated remote attackers to execute arbitrary commands on a victim's local machine by tricking them into visiting a malicious web page. This high-severity vulnerability poses a significant risk to users, particularly those managing sensitive data or critical infrastructure. Organizations using this software should prioritize immediate remediation to mitigate potential exploitation.

CVE
CVE-2026-15027
Severity
HIGH
CVSS
8.8
EPSS
3.16%

Original NVD Description

CGServiSign developed by Changing has a OS Command Injection vulnerability. Unauthenticated remote attackers can induce victims to visit a malicious web page and inject arbitrary OS commands through the local service interface, resulting in command execution on the victim's local computer.