← back

CVE-2026-51990

hype LIKELY HACK · 78 hack

Confirmed in-the-wild exploitation, specific threat actor named, vendor patch released; KEV absence and sparse NVD metadata prevent higher score.

What: Remote code execution in Tencent Sogou Input Method for Windows via malicious sgbiz: URI links; enables one-click RCE and GrayRabbit backdoor deployment.

Why it matters: Active in-the-wild exploitation by UNC3569 (China-aligned espionage group) confirmed across multiple threat intelligence sources. Vendor (Tencent) has patched in version 16.3. No KEV listing yet, but real-world weaponization and defender remediation guidance present. Social chatter consistently cites threat actor activity and malware payload.

Where it's seen: Threat intelligence reports (SecurityCyber, BleepingComputer, TheHackerNews), defender alerts recommending client isolation, vulnerability aggregator posts tracking GrayRabbit deployment chain.

RISK: CRITICAL — Active exploitation by known APT, one-click RCE, widespread Sogou user base, patch available but adoption lag.

Generated by claude-haiku-4-5 from public posts and authoritative metadata. AI can make mistakes — verify against vendor advisories before acting. 9/14/2026, 9:43:08 AM

No NVD details ingested for this CVE yet.