A path traversal vulnerability in Yonyou U8 CRM, identified as CVE-2023-54403, was reportedly exploited on the same day it was publicly disclosed. The vulnerability was reserved as a CVE on September 30, 2026, and published on the same date.
The exploitation of CVE-2023-54403 was first listed in a commercial vulnerability catalog, VulnCheck KEV, on September 30, 2026. This listing was mirrored by the CIRCL aggregator on the same day. However, neither the CISA KEV (US federal) nor the EUVD (ENISA, European Union) catalogs have listed this vulnerability as exploited.
The claim of same-day exploitation relies on a single source, VulnCheck KEV, and has not been independently corroborated by a second major catalog. Public exploitation evidence was reported on September 30, 2026, with one public report collected from VulnCheck and CIRCL, linking to their original sources.
The CVE record for CVE-2023-54403 currently has no assigned CVSS severity score. Its Exploit Prediction Scoring System (EPSS) percentile is 50.9%, indicating a 0.69% probability of exploitation within the next 30 days.
The vulnerability is described as a path traversal flaw, which typically allows an attacker to access files and directories outside of the intended web root or restricted directory. Yonyou U8 CRM is an enterprise resource planning (ERP) and customer relationship management (CRM) software suite widely used in China and other regions.






