Mark RadarMARK RADAR
EN

South Korea’s KISA Launches Proactive Removal Service for Vulnerable WGear Banking Middleware

1 reports · First detected 2026-04-28 · Last active 2026-04-28

WGear is middleware commonly used by South Korean companies for online banking. Older versions contain a remote code execution, or RCE, vulnerability that attackers could exploit to run malicious software, threatening account operations and electronic financial services. The Korea Internet & Security Agency, or KISA, therefore selected WGear as the first target of its proactive removal program.

KISA launched its Vulnerability Removal Service for the first time in April 2026, partnering with four antivirus software vendors to proactively detect and remove older WGear versions containing the vulnerability through their antivirus products. The initiative marks a shift from issuing warnings and asking users to install updates themselves to directly helping remove risky software.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR