CVE-2023-4528: Redwood Jscape MFT

High severity, CVSS 7.2. EPSS: 31.9% chance of exploitation in the next 30 days.

Unsafe deserialization in JSCAPE MFT Server versions prior to 2023.1.9 (Windows, Linux, and MacOS) permits an attacker to run arbitrary Java code (including OS commands) via its management interface

Affected products

  • Redwood Jscape MFT: before 2023.1.9 (fixed in 2023.1.9)

Published 2023-09-07. Last modified 2026-06-17.