TWCERT/CC disclosed three critical vulnerabilities in BorG Technology Corporation's Borg SPM 2007 that can be exploited remotely without authentication. The issues are tracked as CVE-2026-6885, an arbitrary file upload flaw mapped to CWE-434 that allows attackers to upload and execute web shell backdoors; CVE-2026-6886, an authentication bypass mapped to CWE-1390 that lets attackers log in as any user; and CVE-2026-6887, a SQL injection flaw mapped to CWE-89 that enables arbitrary SQL commands against the backend database.
All three vulnerabilities carry high-severity impact ratings with CVSS v3.1 vectors of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating low-complexity network exploitation with no privileges or user interaction required. Successful attacks could lead to arbitrary code execution, unauthorized account access, and the reading, modification, or deletion of database contents, creating a path to full compromise of exposed Borg SPM 2007 deployments. The product is described as having ended sales in 2008, but systems still in operation remain at risk.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
TWCERT/CC published advisory references in both English and Chinese for CVE-2026-6885, CVE-2026-6886, and CVE-2026-6887. These advisories publicly documented the vulnerabilities and their impact on Borg SPM 2007.
A CVE entry was published for a SQL injection vulnerability in Borg SPM 2007 that allows unauthenticated remote attackers to inject arbitrary SQL commands and read, modify, or delete database contents. The issue was classified as CWE-89 and assigned a critical CVSS v3.1 vector reflecting high impact across confidentiality, integrity, and availability.
A CVE entry was published for an authentication bypass vulnerability in Borg SPM 2007 that allows unauthenticated remote attackers to log in as any user. The flaw was mapped to CWE-1390 and assigned a critical CVSS v3.1 vector indicating remote exploitation with no privileges or user interaction required.
A CVE entry was published for an arbitrary file upload vulnerability in Borg SPM 2007 that allows unauthenticated remote attackers to upload and execute web shell backdoors on the server. The issue was mapped to CWE-434 and assigned a critical CVSS v3.1 score vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
On April 23, 2026, twcert@cert.org.tw received reports for three critical vulnerabilities affecting Borg SPM 2007: an arbitrary file upload flaw, an authentication bypass, and a SQL injection issue. All three vulnerabilities can be exploited remotely without authentication and carry high confidentiality, integrity, and availability impact.
BorG Technology Corporation's Borg SPM 2007 product is noted in the advisories as having ended sales in 2008. This provides product lifecycle context for the later-disclosed vulnerabilities.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.