CVE-2026-51990

Critical9.8Published on September 16, 2026

An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote attacker to execute arbitrary code via the biz_helper.exe component

Early warning: exploitation observed

  • Exploitation observed since Sep 10, 2026
  • Not yet in the official CISA catalogue
  • Attacked 7 days before the vulnerability was made public

Source: VulnCheck KEV · Sep 10, 2026

CVSS score9.8 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness type (CWE)CWE-94

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database