CERT Polska disclosed two vulnerabilities in Asseco proCertum SmartSign that can be triggered through crafted certificates and signature files. CVE-2026-57916 is a CWE-73 weakness caused by opening a Certificate Practice Statement URI without validating its schema, allowing an attacker to prepare a certificate that launches a local file or opens a remote URL when a victim opens a signed document. The issue reflects the broader risk of externally controlled file names or paths, which can lead to unauthorized file access, modification, or code execution.
CERT Polska also reported CVE-2026-57917, an XXE flaw (CWE-611) in SmartSign's handling of XML signatures. A crafted signature file can force the application to resolve external entities, enabling SSRF and, depending on parser settings, possible local file disclosure; the bug may be triggered even when a user only previews a file in the selection window before opening it. Both vulnerabilities affect versions prior to 9.4.3.90 and were fixed in 9.4.3.90; the issues were responsibly reported by Mariusz Maik.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-27, CERT Polska published two vulnerabilities in proCertum SmartSign: CVE-2026-57916, a CWE-73 issue involving unsafe URI schema handling, and CVE-2026-57917, an XXE flaw that can enable SSRF and possible local file reads.
CERT Polska reported that both vulnerabilities affected all proCertum SmartSign versions before 9.4.3.90 and were fixed in version 9.4.3.90.
CERT Polska said it coordinated disclosure of two vulnerabilities affecting Asseco proCertum SmartSign, and credited Mariusz Maik for responsibly reporting the issues.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecert.pl
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.