HIGH
Latvijas Valsts radio un televīzijas centrs (LVRTC)
CVE published 2026-08-03
CVE-2026-0392
The eParakstītājs 3.0 for Windows application has a critical vulnerability (CVE-2026-0392) that allows for arbitrary code execution due to an insecure update mechanism. This mechanism accepts any TLS certificate and does not verify digital signatures or checksums before executing downloaded installers. Affected deployments should prioritize updating to version 1.10.0 or later. The vulnerability impacts op [truncated]