Cyber News / Article / Vulnerabilities in proCertum SmartSign software

Vulnerabilities in proCertum SmartSign software
CERT Polska has received a report about vulnerabilities in proCertum SmartSign software and participated in coordination of their disclosure.
The vulnerabilityCVE-2026-57916: proCertum SmartSign opens Certificate Practice Statement (CPS) URI without schema validation. An attacker can prepare arbitrary certificate with CPS URI pointing to a local executable file or any URL, sign a document with it, and send it to the victim. When the victim opens the document in the application, the specified file will be executed (or webpage will be opened).
The vulnerabilityCVE-2026-57917: proCertum SmartSign parses external XML entities from arbitrary crafted signature files, enabling SSRF and potentially allowing the reading of local files, depending on the parser's configuration. The XML External Entity (XXE) vulnerability is triggered simply by previewing a file in the file selection window, before the victim clicks âOpenâ.
These issues were fixed in version 9.4.3.90.
We thank Mariusz Maik for the responsible vulnerability report.
Related articles
Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data
8 days ago
Top 10 Best Patch Management Software in 2026
2 days ago
September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs
3 days ago
You might Also like

Hackers Target Claude, Cursor and Codex AI Agents to Steal Tokens and Prompt Histories

DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval

