ZeroHour

CVE-2026-7861

niche

Unauthenticated Deserialization RCE in Next4Biz CSM

CVSS 3.1
9.8 critical
EPSS
<1%p25
Published
()
Modified
AI analysis

Next4Biz CSM (Customer Service Management) versions before 8.0.3 deserialize untrusted data without validation (CWE-502), allowing attackers to inject and execute arbitrary code. The flaw is triggered by sending crafted serialized data to the network-facing application, with no authentication, privileges, or user interaction required (CVSS 3.1: AV:N/AC:L/PR:N/UI:N). A successful attack yields full compromise of the hosting server, with high impact to confidentiality, integrity, and availability, effectively enabling remote code execution. Any organization running an affected version of Next4Biz CSM is at risk, particularly instances exposed to the internet. No public proof-of-concept or confirmed exploitation is known; EPSS currently estimates only a ~0.3% probability of exploitation within 30 days, and the issue is not in CISA KEV.

What to do: Upgrade Next4Biz CSM to version 8.0.3 or later. Until patched, restrict network access to the CSM instance (e.g., firewall rules, VPN, or WAF filtering of serialized input) and avoid exposing it directly to the internet. Monitor vendor advisories and server logs for signs of unexpected deserialization traffic or code execution.

Affected
Next4Biz Information Technologies Inc. CSM (Customer Service Management)before 8.0.3
Estimated exposure
nichelikely low hundreds to a few thousand enterprise deployments (niche B2B product; no public install counts) — Next4Biz CSM is a specialized customer service platform from a Turkish enterprise software vendor typically deployed per-organization, and no public install-base counts or internet-scan data are available, so the estimate relies on…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Code Injection. This issue affects CSM (Customer Service Management): before 8.0.3.

Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.