Forwarded from Taiwan Computer Emergency Response Team / Coordination Center (TWCERT/CC) Security Alert: TWCERTCC-200-202604-00000026
【Borg Technology|Borg SPM 2007 - Arbitrary File Upload】(CVE-2026-6885, CVSS: 9.8) An unauthenticated remote attacker can upload and execute web backdoors, thereby executing arbitrary code on the server side.
【Borg Technology|Borg SPM 2007 - Authentication Bypass】(CVE-2026-6886, CVSS: 9.8) An unauthenticated remote attacker can log into the system as any user.
【Borg Technology|Borg SPM 2007 - SQL Injection】(CVE-2026-6887, CVSS: 9.8) An unauthenticated remote attacker can inject arbitrary SQL commands to read, modify, and delete database content.