Review reviewHigh
CVE-2026-27648
OpenHarmony
in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps.
- CVSS
- 8.8
- EPSS
- 0.55% 43.0% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.19
in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps.
The CVSS severity warrants an early asset and exposure review.
in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps.
Confirm exposure before applying a vendor-supported change.
Confirm that OpenHarmony and an affected version are present.
Combine exploitation signals with asset exposure and business criticality.
Follow the vendor advisory or supported update path and preserve rollback options.
Recheck the version, service health, access paths, and relevant logs.