CVE-2025-70888: Osslsigncode Project Osslsigncode

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

An issue in mtrojnar Osslsigncode affected at v2.10 and before allows a remote attacker to escalate privileges via the osslsigncode.c component

Affected products

Published 2026-03-25. Last modified 2026-06-17.