High severity8.8NVD Advisory· Published Sep 23, 2026
CVE-2026-15027
CVE-2026-15027
Description
CGServiSign developed by Changing has a OS Command Injection vulnerability. Unauthenticated remote attackers can induce victims to visit a malicious web page and inject arbitrary OS commands through the local service interface, resulting in command execution on the victim's local computer.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.