What is CVE-2026-75987?
A deserialization vulnerability was found in SPLWare esProc, specifically within the ObjectInputStream.readUnshared function. This flaw allows for possible remote code execution through manipulation of serialized objects. Users are advised to apply the vendor-provided patch.
Azərbaycanca: SPLWare esProc proqramında deserialization zəifliyi aşkarlanıb. Bu boşluq xüsusilə ObjectInputStream.readUnshared funksiyası vasitəsilə uzaqdan kod icrasına imkan yaradır. İstifadəçilərə tövsiyə olunur ki, istehsalçı tərəfindən təmin edilən yeniləməni tətbiq etsinlər.
Related CVEs
link basis: same weakness class CWE-502
FAQ1
Which function in SPLWare esProc is associated with the remote code execution vulnerability tracked as CVE-2026-75987?
The deserialization vulnerability is specifically associated with the ObjectInputStream.readUnshared function, allowing for possible remote code execution.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.