CVE-2026-5965Disclosure

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-21: 3PoC Mentioned / Linked · 2026-04-21: 1Patch / Workaround · 2026-04-21: 1Technical Details · 2026-04-21: 304-21
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
Full discourse3 posts
  • Orizon@OrizonCyber
    Disclosure

    🚨 CVE-2026-5965 — CVSS 9.8/10 ██████████ NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/KXgGSaHqr5

    Post summary

    A disclosure of CVE-2026-5965, an unauthenticated local OS command injection in NewSoftOA with high CVSS score; a patch is now available.

    1000050
    28 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5965 NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on t… https://www.cve.org/CVERecord?id=CVE-2026-5965

    Post summary

    The post announces CVE-2026-5965, an OS Command Injection flaw in NewSoftOA that permits unauthenticated local attackers to execute arbitrary commands.

    0000065
    57.2K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-5965: NewSo... Unauthenticated RCE with 9.3 CVSS on enterprise OA systems - perfect pivot point for lateral movement in corporate networks. #RCE #CommandInjection. https://zerodaysignal.com/vulnerability/CVE-2026-5965 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A new high‑severity, unauthenticated RCE (CVE‑2026‑5965) is announced, with a link to the vulnerability details but no exploit code, active exploitation, or patch information provided.

    0000086
    218 followersView on X

Explore more