External risk intelligence

Dormakaba Evolo Service SYSTEM Code Execution Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-37719

The affected product is a service utility for access control hardware, typically deployed within internal facility management networks to configure physical security devices. While network-reachable in some environments, it is not a common internet-facing gateway or public service, and is usually protected by internal network controls.

Deserialization

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

An unspecified .NET component in dormakaba evolo Service is vulnerable to remote code execution, potentially allowing unauthorized system-level control. The main concern is confirming relevance and exposure to our specific deployment.

  • Allows code execution via remote attack.
  • Matters for potential unauthorized system control.
  • Confirm relevance and exposure to our systems.

Attack Path

How an attacker could exploit the issue

An attacker can exploit a vulnerability in dormakaba evolo Service by remotely sending specially crafted data through a .NET component. This allows them to execute any code with the highest system privileges.

  • No authentication or user interaction needed.
  • Triggered by sending malicious data.
  • Allows arbitrary SYSTEM code execution.

Live Threat

Current exploitation, exposure, and threat context

A remote attacker could execute arbitrary code with SYSTEM privileges on a system running dormakaba evolo Service. This could occur when the service is accessible over a network.

  • System-level code execution on the affected device.
  • Remote code execution via network access.
  • Compromise of the host system.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in dormakaba evolo Service could allow remote code execution as SYSTEM. Identifying where this service is deployed, assessing its business criticality and network reachability, and locating the accountable owner are the crucial first steps. Remediation planning should then proceed based on the identified risk.

  • System owners and infrastructure teams.
  • Verify network reachability and criticality.
  • Plan remediation based on exposure.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the dormakaba evolo Service?

The dormakaba evolo Service is a management utility designed to configure and maintain physical access control hardware, such as electronic locks and door readers. It functions as a specialized software component within facility management environments, ensuring that digital credentials and security settings are correctly synchronized across an organization's physical security infrastructure.

What does CWE-502 mean for CVE-2026-37719?

CWE-502 refers to Deserialization of Untrusted Data. In this vulnerability, the software incorrectly processes serialized data sent by a remote attacker. Because the .NET component does not safely validate this incoming information, the system interprets the malicious data as legitimate commands, inadvertently granting the attacker the ability to execute arbitrary code with full system-level privileges.

How is this code execution triggered?

An attacker triggers this vulnerability by sending specially crafted data packets over the network to the affected service. The process does not require the attacker to have an existing account, nor does it require any assistance from a local user. Simply having the service reachable and capable of receiving this specific type of network input is sufficient to initiate the flaw; local file access or physical proximity is not necessary.

Is my environment at risk according to Halo Surface Signal?

Halo Surface Signal notes that while this service is network-reachable, it is generally intended for internal facility management rather than public-facing internet use. Because it typically sits behind internal network controls, the likelihood of an external, internet-based attack is considered low. You should prioritize checking if your deployment is accidentally exposed outside of those protected internal segments.

What should I do first to manage this risk?

Start by identifying all servers or workstations running the evolo Service. Once located, verify their network accessibility to determine if they are exposed to untrusted segments. Document the business criticality of the associated security hardware and confirm who owns the system. With this inventory and connectivity data, you can build a targeted remediation plan to isolate or update the affected infrastructure.

References