CVE-2026-3422: Edetw U-Office Force

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

U-Office Force developed by e-Excellence has a Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server by sending maliciously crafted serialized content.

Affected products

  • Edetw U-Office Force: before 29.50 (fixed in 29.50); version 29.50 only

Published 2026-03-02. Last modified 2026-06-17.