CVE-2026-15027: Changing Cgservisign
High severity, CVSS 8.8. EPSS: 3.2% chance of exploitation in the next 30 days.
CGServiSign developed by Changing has a OS Command Injection vulnerability. Unauthenticated remote attackers can induce victims to visit a malicious web page and inject arbitrary OS commands through the local service interface, resulting in command execution on the victim's local computer.
Affected products
- Changing Cgservisign: version 1.0.23.1227 only
Published 2026-09-23. Last modified 2026-09-24.