CVE-2026-51990
Confirmed in-the-wild exploitation, specific threat actor named, vendor patch released; KEV absence and sparse NVD metadata prevent higher score.
What: Remote code execution in Tencent Sogou Input Method for Windows via malicious sgbiz: URI links; enables one-click RCE and GrayRabbit backdoor deployment.
Why it matters: Active in-the-wild exploitation by UNC3569 (China-aligned espionage group) confirmed across multiple threat intelligence sources. Vendor (Tencent) has patched in version 16.3. No KEV listing yet, but real-world weaponization and defender remediation guidance present. Social chatter consistently cites threat actor activity and malware payload.
Where it's seen: Threat intelligence reports (SecurityCyber, BleepingComputer, TheHackerNews), defender alerts recommending client isolation, vulnerability aggregator posts tracking GrayRabbit deployment chain.
RISK: CRITICAL — Active exploitation by known APT, one-click RCE, widespread Sogou user base, patch available but adoption lag.
No NVD details ingested for this CVE yet.