PULSE
FEED
ransomplay reclama a Bold Spring Nursery · US · Agriculture and Food Productionransomplay reclama a Silicon Valley Glass · US · Manufacturingransomemperador reclama a OMUR HIRDAVAT LTD · TR · Manufacturingransombooba project reclama a MorseLife Health System, Inc. · US · Healthcareransomstorm reclama a Nipigon District Memorial Hospital · CA · Healthcareransomqilin reclama a Unident Group · US · Otherransomqilin reclama a Chadwick Switchboards · AU · Manufacturingransomqilin reclama a Emser · ES · Manufacturingransomqilin reclama a Cotesma · CL · Manufacturingransomdirewolf reclama a Softruck · BR · Technologyransomqilin reclama a Mutsumi Group · JP · Manufacturingransompayoutsking reclama a M****C · US · Not Foundransomthegentlemen reclama a Center State Engineering · US · Manufacturingransomkrybit reclama a euroditel.com · FR · Technologyransomplay reclama a Bold Spring Nursery · US · Agriculture and Food Productionransomplay reclama a Silicon Valley Glass · US · Manufacturingransomemperador reclama a OMUR HIRDAVAT LTD · TR · Manufacturingransombooba project reclama a MorseLife Health System, Inc. · US · Healthcareransomstorm reclama a Nipigon District Memorial Hospital · CA · Healthcareransomqilin reclama a Unident Group · US · Otherransomqilin reclama a Chadwick Switchboards · AU · Manufacturingransomqilin reclama a Emser · ES · Manufacturingransomqilin reclama a Cotesma · CL · Manufacturingransomdirewolf reclama a Softruck · BR · Technologyransomqilin reclama a Mutsumi Group · JP · Manufacturingransompayoutsking reclama a M****C · US · Not Foundransomthegentlemen reclama a Center State Engineering · US · Manufacturingransomkrybit reclama a euroditel.com · FR · Technology
← All CVEs
CVE WatchOct 5, 2026

CVE-2026-20589

In venc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege if a malicious acto

CVSS

—

No CVSS

EPSS

—

KEV

—

Exploit Today

—

0-100

Published: Oct 5, 2026 · Last modified: Oct 5, 2026 · CWE-787

EPSS · 30d

Not enough EPSS history yet.

Technical description

In venc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11383899; Issue ID: MSV-9606.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-20588—
—
———In mtee, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11383899; Issue ID: MSV-9607.7h
CVE-2026-20586—
—
———In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS11383899; Issue ID: MSV-9614.7h
CVE-2026-20579—
—
———In vdec, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11383899; Issue ID: MSV-9800.7h
CVE-2026-20544—
—
———In meta, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11049530 / ALPS11480843; Issue ID: MSV-7935.7h
CVE-2026-20530—
—
———In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11292777; Issue ID: MSV-9195.7h
CVE-2026-20529—
—
———In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11276677; Issue ID: MSV-9217.7h