CVE-2026-3422: Edetw U-Office Force
Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.
U-Office Force developed by e-Excellence has a Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server by sending maliciously crafted serialized content.
Affected products
- Edetw U-Office Force: before 29.50 (fixed in 29.50); version 29.50 only
Published 2026-03-02. Last modified 2026-06-17.