CVE-2025-66837: Softwareag Aris

Medium severity, CVSS 6.8. EPSS: 0.3% chance of exploitation in the next 30 days.

A file upload vulnerability in ARIS 10.0.23.0.3587512 allows attackers to execute arbitrary code via uploading a crafted PDF file/Malware

Affected products

  • Softwareag Aris: up to and including 10.0.23.0.3587512

Published 2026-01-07. Last modified 2026-06-17.