EPSS 0.00 (nejvyšší)
Multiple vulnerabilities in SOY series
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-73827, CVE-2026-77838, CVE-2026-78238, CVE-2026-78032, Summary: SOY series provided by Tsuyoshi Saito contain multiple vulnerabilities listed below. Cross-site Scripting (CWE-79) - CVE-2026-73827, CVE-2026-77838, CVE-2026-78238 Deserialization of Untrusted Data (CWE-502) - CVE-2026-78032 An arbitrary script may be executed on the web browser of the user who is logging in to the product…
CVE v události 4
| CVE | hodnocení | KEV | EPSS |
|---|---|---|---|
| CVE-2026-73827 | 5.4 3.0 · jpcert 4.8 4.0 · jpcert | – | 0.00 |
| CVE-2026-77838 | 5.4 3.0 · jpcert 4.8 4.0 · jpcert | – | 0.00 |
| CVE-2026-78032 | 9.8 3.0 · jpcert 9.3 4.0 · jpcert | – | 0.00 |
| CVE-2026-78238 | 5.4 3.0 · jpcert 4.8 4.0 · jpcert | – | 0.00 |
Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 9.8.
Jak se o tom psalo 1
-
· NCSC-FI FI nadpis události
Multiple vulnerabilities in SOY series
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-73827, CVE-2026-77838, CVE-2026-78238, CVE-2026-78032, Summary: SOY series provided by Tsuyoshi Saito contain multiple vulnerabilities listed below. Cross-site Scripting (CWE-79) - CVE-2026-73827, CVE-2026-77838, CVE-2026-78238 Deserialization of Untrusted Data (CWE-502) - CVE-2026-78032 An arbitrary script may be executed on the web browser of the user who is logging in to the product…