CVE-2026-37719: Dormakaba evolo Service vulnerability
Published Oct 5, 2026
·Updated
An issue in dormakaba evolo Service (all versions) allows a remote attacker to execute arbitrary code as SYSTEM via a .NET component.
Affected Software
1 affected component
dormakaba evolo Service
Event History
Oct 5, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
Which versions are affected?
The issue is reported to affect all versions of dormakaba evolo Service.
2
What level of access could an attacker obtain?
A remote attacker could execute arbitrary code with SYSTEM privileges.
3
What component is implicated in the issue?
The vulnerability is associated with a .NET component in dormakaba evolo Service.