ZeroHour

Vulnerabilities

290 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-20504
In Modem, there is a possible system crash due to a missing bounds check.

In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00755024; Issue ID: MSV-7865.

NVD description · AI analysis pending
5.3<1%
  • mediatek mt2735 firmware
  • mediatek mt6833 firmware
  • mediatek mt6853 firmware
  • +1 more
CVE-2026-20500
+1 in the same advisory: …20503
In Modem, there is a possible system crash due to improper input validation.

In Modem, there is a possible system crash due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01810811; Issue ID: MSV-9232.

NVD description · AI analysis pending
5.5
group max
<1%
  • mediatek mt2716 firmware
  • mediatek mt6835 firmware
  • mediatek mt6858 firmware
  • +1 more
CVE-2026-20501
+1 in the same advisory: …20502
Heap buffer overflow in MediaTek vdec firmware enables local privilege escalation

CVE-2026-20501 is a heap-based buffer overflow (CWE-122) in the vdec (video decoder) component of firmware for a wide range of MediaTek chipsets, which can cause an out-of-bounds write when crafted data is processed by the decoder. A local attacker with no additional execution privileges — for example a low-privileged app or process on the device — could exploit it without any user interaction to gain elevated privileges. Affected devices are those running firmware for the listed MediaTek SoCs (MT2718, MT6580, MT6739, MT6761, MT6765, MT6768, MT6769, MT6779, MT6781, MT6785, MT6789 and MT6833), chips commonly found in budget Android smartphones, feature phones, smart TVs and other consumer/IoT hardware. There is no evidence of active exploitation: the flaw is not in CISA KEV, has an EPSS 30-day probability of about 0.1% (3rd percentile), and no public proof-of-concept is known. The fix ships via MediaTek/OEM firmware updates associated with Patch ID ALPS11262030 (Issue ID MSV-9197).

Do: Apply the fixed firmware containing MediaTek patch ALPS11262030 (Issue MSV-9197) as soon as your device OEM or carrier ships it, and check your device's chipset against the affected list in vendor security bulletins. Because exploitation requires local code execution, the practical risk before patching is limited to attackers who can already run an app or process on the device, so avoid installing untrusted apps on affected devices. Organizations managing fleets of MediaTek-based phones, TVs or IoT hardware should prioritize OEM update rollouts for the listed SoCs.

8.4<1%
  • MediaTek MT2718 firmware
  • MediaTek MT6580 firmware
  • MediaTek MT6739 firmware
  • +9 more
massTens of millions of devices globally (order-of-magnitude estimate)
CVE-2026-20473
+4 in the same advisory: …20498 …20474 …20489 …20488
In display, there is a possible memory corruption due to use after free.

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11019722; Issue ID: MSV-7759.

NVD description · AI analysis pending
6.0
group max
<1%
  • mediatek mt6991 firmware
  • mediatek mt8910 firmware
  • mediatek mt6993 firmware
  • +1 more
CVE-2026-20497
+1 in the same advisory: …20481
In geniezone, there is a possible out of bounds write due to a missing bounds check.

In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10965550 / ALPS11393405; Issue ID: MSV-6941.

NVD description · AI analysis pending
6.0<1%
  • mediatek mt6989 firmware
  • mediatek mt8755 firmware
  • mediatek mt8768 firmware
  • +1 more
CVE-2026-20496
In geniezone, there is a possible out of bounds read due to a missing bounds check.

In geniezone, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11036877; Issue ID: MSV-7132.

NVD description · AI analysis pending
4.4<1%
  • mediatek mt6983 firmware
  • mediatek mt8676 firmware
  • mediatek mt8678 firmware
  • +1 more
CVE-2026-20495
In Bluetooth driver, there is a possible permission bypass due to a missing permission check.

In Bluetooth driver, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00488300; Issue ID: MSV-7296.

NVD description · AI analysis pending
7.8<1%
  • mediatek mt7925 firmware
  • mediatek mt7927 firmware
  • mediatek mt7902 firmware
  • +1 more
CVE-2026-20494
+1 in the same advisory: …20493
In wifi, there is a possible out of bounds read due to a missing bounds check.

In wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10960006 / BORA00155314, BORA00155001, BORA00154907; Issue ID: MSV-7570.

NVD description · AI analysis pending
5.5
group max
<1%
  • mediatek mt6890 firmware
  • mediatek mt6988 firmware
  • mediatek mt6990 firmware
CVE-2026-20492
In Audio HAL, there is a possible system becoming unresponsive due to a race condition.

In Audio HAL, there is a possible system becoming unresponsive due to a race condition. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10960026 (Note: For MT6880, MT6890, MT6990, MT6988) / AUTO00851250 (Note: For MT2735, MT2737); Issue ID: MSV-7583.

NVD description · AI analysis pending
5.5<1%
  • mediatek mt6990 firmware
  • mediatek mt2735 firmware
  • mediatek mt2737 firmware
  • +1 more
CVE-2026-20479
+2 in the same advisory: …20478 …20491
In Modem, there is a possible out of bounds read due to a missing bounds check.

In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00741071; Issue ID: MSV-7620.

NVD description · AI analysis pending
7.5
group max
<1%
  • mediatek mt2735 firmware
  • mediatek mt6833 firmware
  • mediatek mt6853 firmware
  • +1 more
CVE-2026-20490
In ccci, there is a possible out of bounds read due to a missing bounds check.

In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10981501; Issue ID: MSV-7669.

NVD description · AI analysis pending
4.4<1%
  • mediatek mt6813 firmware
  • mediatek mt6982vb firmware
  • mediatek mt6986 firmware
  • +1 more
CVE-2026-20486
+2 in the same advisory: …20477 …20475
In imgsensor, there is a possible application crash due to incorrect error handling.

In imgsensor, there is a possible application crash due to incorrect error handling. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11012302; Issue ID: MSV-7833.

NVD description · AI analysis pending
6.7
group max
<1%
  • mediatek mt8910 firmware
  • mediatek mt2718 firmware
  • mediatek mt6878 firmware
  • +1 more
CVE-2026-20485
In HFRP, there is a possible out of bounds write due to a missing bounds check.

In HFRP, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11049569; Issue ID: MSV-7931.

NVD description · AI analysis pending
6.0<1%
  • mediatek mt6993 firmware
CVE-2026-20484
In TFA, there is a possible information disclosure due to a missing permission check.

In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11053160; Issue ID: MSV-8004.

NVD description · AI analysis pending
4.4<1%
  • mediatek mt8799 firmware
  • mediatek mt6739 firmware
  • mediatek mt6761 firmware
  • +1 more
CVE-2026-20483
In Telephony, there is a possible escalation of privilege due to a missing permission check.

In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11087526; Issue ID: MSV-8243.

NVD description · AI analysis pending
7.7<1%
  • mediatek mt8893 firmware
  • mediatek mt6739 firmware
  • mediatek mt6761 firmware
  • +1 more
CVE-2026-20482
In wlan STA FW, there is a possible system becoming unresponsive due to logging.

In wlan STA FW, there is a possible system becoming unresponsive due to logging. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00486814; Issue ID: MSV-6824.

NVD description · AI analysis pending
6.5<1%
  • mediatek mt8532 firmware
  • mediatek mt7902 firmware
  • mediatek mt7921 firmware
  • +1 more
CVE-2026-20480
In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow.

In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10960023 (Note: For MT6880, MT6890, MT6980D, MT6988, MT6990) / AUTO00851189 (Note: For MT2735, MT3737); Issue ID: MSV-7586.

NVD description · AI analysis pending
5.5<1%
  • mediatek mt6880 firmware
  • mediatek mt2735 firmware
  • mediatek mt2737 firmware
  • +1 more
CVE-2026-20476
In ccci, there is a possible out of bounds read due to a missing bounds check.

In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981532; Issue ID: MSV-7660.

NVD description · AI analysis pending
5.5<1%
  • mediatek mt6988 firmware
  • mediatek mt6813 firmware
  • mediatek mt6986 firmware
CVE-2026-20456
In wlan STA driver, there is a possible system crash due to a missing bounds check.

In wlan STA driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00480851; Issue ID: MSV-6338.

NVD description · AI analysis pending
5.5<1%
  • mediatek mt7902 firmware
  • mediatek mt7920 firmware
  • mediatek mt7921 firmware
  • +1 more
CVE-2026-20455
In geniezone, there is a possible out of bounds write due to a missing bounds check.

In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10873936; Issue ID: MSV-6784.

NVD description · AI analysis pending
7.8<1%
  • mediatek mt6739 firmware
  • mediatek mt6761 firmware
  • mediatek mt6765 firmware
  • +1 more
CVE-2026-20453
+1 in the same advisory: …20454
In geniezone, there is a possible out of bounds write due to a missing bounds check.

In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10886526; Issue ID: MSV-6791.

NVD description · AI analysis pending
6.7
group max
<1%
  • mediatek mt8673 firmware
  • mediatek mt8765 firmware
  • mediatek mt8766 firmware
  • +1 more
CVE-2026-20452
In wlan AP driver, there is a possible memory corruption due to a heap buffer overflow.

In wlan AP driver, there is a possible memory corruption due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00480138; Issue ID: MSV-6295.

NVD description · AI analysis pending
8.0<1%
  • mediatek mt6890 firmware
  • mediatek mt7615 firmware
  • mediatek mt7915 firmware
  • +1 more
CVE-2026-20451
In slbc, there is a possible out of bounds write due to type confusion.

In slbc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10828685; Issue ID: MSV-6504.

NVD description · AI analysis pending
6.7<1%
  • mediatek mt8115 firmware
  • mediatek mt8186 firmware
  • mediatek mt8188 firmware
  • +1 more
CVE-2026-20450
In Modem, there is a possible system crash due to incorrect error handling.

In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01753620; Issue ID: MSV-6100.

NVD description · AI analysis pending
6.5<1%
  • mediatek mt2735 firmware
  • mediatek mt2737 firmware
  • mediatek mt6833 firmware
  • +1 more
CVE-2026-20449
In Modem, there is a possible system crash due to a heap buffer overflow.

In Modem, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01760138; Issue ID: MSV-6148.

NVD description · AI analysis pending
6.5<1%
  • mediatek mt6763 firmware
  • mediatek mt6765 firmware
  • mediatek mt6767 firmware
  • +1 more
CVE-2026-20448
In geniezone, there is a possible escalation of privilege due to a missing permission check.

In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10708513; Issue ID: MSV-6281.

NVD description · AI analysis pending
6.7<1%
  • mediatek mt6765 firmware
  • mediatek mt6768 firmware
  • mediatek mt6789 firmware
  • +1 more
CVE-2026-20447
In geniezone, there is a possible escalation of privilege due to a missing bounds check.

In geniezone, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10724073; Issue ID: MSV-6296.

NVD description · AI analysis pending
6.7<1%
  • mediatek mt6768 firmware
  • mediatek mt6789 firmware
  • mediatek mt6877 firmware
  • +1 more
CVE-2026-20431
+1 in the same advisory: …20446
In Modem, there is a possible system crash due to a logic error.

In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01106496; Issue ID: MSV-4467.

NVD description · AI analysis pending
6.5
group max
<1%
  • mediatek mt6813 firmware
  • mediatek mt6815 firmware
  • mediatek mt6835 firmware
  • +1 more
CVE-2026-20433
+1 in the same advisory: …20432
In Modem, there is a possible out of bounds write due to a missing bounds check.

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01088681; Issue ID: MSV-4460.

NVD description · AI analysis pending
8.8
group max
<1%
  • mediatek mt2735 firmware
  • mediatek mt2737 firmware
  • mediatek mt6813 firmware
  • +1 more
CVE-2026-20423
+1 in the same advisory: …20436
In wlan STA driver, there is a possible out of bounds write due to a missing bounds check.

In wlan STA driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00465314; Issue ID: MSV-4956.

NVD description · AI analysis pending
7.8
group max
<1%
  • mediatek nbiot sdk
CVE-2026-20434
In Modem, there is a possible out of bounds write due to a missing bounds check.

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY00782946; Issue ID: MSV-4135.

NVD description · AI analysis pending
7.5<1%
  • mediatek lr12a
  • mediatek lr13
  • mediatek nr15
  • +1 more
CVE-2026-20430
In wlan AP FW, there is a possible out of bounds write due to an incorrect bounds check.

In wlan AP FW, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00467553; Issue ID: MSV-5151.

NVD description · AI analysis pending
8.8<1%
  • mediatek software development kit
  • mediatek openwrt
CVE-2026-20422
+1 in the same advisory: …20421
In Modem, there is a possible system crash due to improper input validation.

In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00827332; Issue ID: MSV-5919.

NVD description · AI analysis pending
6.5<1%
  • mediatek nr15
  • mediatek nr16
  • mediatek nr17
  • +1 more