CVE-2026-51990
An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote attacker to execute arbitrary code via the biz_helper.exe component
Early warning: exploitation observed
- Exploitation observed since Sep 10, 2026
- Not yet in the official CISA catalogue
- Attacked 7 days before the vulnerability was made public
Source: VulnCheck KEV · Sep 10, 2026
CVSS score9.8 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeakness type (CWE)CWE-94
Related articles
APTUNC3569 Exploited Sogou Input Method to Install GRAYRABBIT Backdoor
UNC3569 exploited Sogou Input Method's sgbiz protocol and outdated Chromium browser to execute code and deploy GRAYRABBIT backdoor via DLL sideloading.
VulnerabilitiesTencent Sogou Input Flaw Exploited for One-Click System-Level Code Execution
China-linked UNC3569 exploited CVE-2026-51990 in Tencent Sogou Input via crafted sgbiz:// link to execute code as SYSTEM and deploy GrayRabbit backdoor.
This product uses the NVD API but is not endorsed or certified by the NVD.