Posting Date: 2026/09/03

【Vulnerability Alert】Think Software Technology|EFence - Arbitrary File Upload

  • Subject: 【Vulnerability Alert】Think Software Technology|EFence - Arbitrary File Upload


  • Content:
    • Forwarded from Taiwan Computer Emergency Response Team/Coordination Center Security Alert TWCERTCC-200-202608-00000020
    • 【Think Software Technology|EFence - Arbitrary File Upload】(CVE-2026-80235, CVSS: 9.8) An unauthenticated remote attacker can upload and execute web webshells, thereby executing arbitrary code on the server side.
    • 【Think Software Technology|EFence - Arbitrary File Upload】(CVE-2026-80237, CVSS: 8.8) An authenticated remote attacker can upload and execute web webshells, thereby executing arbitrary code on the server side.
  • Affected Platforms:
    • EFence version 1.2.66 DB Ver:56 and earlier versions
  • Recommendations:
    • Please update to version 1.2.67 DB Ver:57 or later
  • References:

Computer and Communication Center
Network System Division Respectfully