


Perceptive Security
SOC/SIEM Consultancy

U-Office Force developed by e-Excellence has a Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on th…
Published:
1 maart 2026 om 23:00:00
Alert date:
2 maart 2026 om 08:01:55
Source:
nvd.nist.gov
Enterprise Applications
U-Office Force developed by e-Excellence contains an insecure deserialization vulnerability identified as CVE-2026-3422. The vulnerability allows unauthenticated remote attackers to execute arbitrary code on the server by sending maliciously crafted serialized content. This represents a critical security flaw as it enables remote code execution without authentication. The vulnerability affects the U-Office Force application and poses significant risk to organizations using this software. Attackers can exploit this flaw to gain unauthorized access and control over affected systems.
Technical details
Mitigation steps:
Affected products:
U-Office Force
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-3422
https://www.twcert.org.tw/en/cp-139-10743-9a952-2.html
https://www.twcert.org.tw/tw/cp-132-10742-45b13-1.html
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
