SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-21040

MEDIUM · CVSS 6.9 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

Improper access control in IAFDService prior to the SMR Jul-2026 Release 1 enables local privileged attackers to exploit privileged APIs, potentially leading to unauthorized access and manipulation of sensitive system functions. Organizations using affected versions of IAFDService should prioritize this vulnerability to mitigate risks associated with local privilege escalation. Immediate action is recommended for environments where local access is possible, particularly in sensitive or critical infrastructure settings.

CVE
CVE-2026-21040
Severity
MEDIUM
CVSS
6.9
EPSS
0.10%

Original NVD Description

Improper access control in IAFDService prior to SMR Jul-2026 Release 1 allows local privileged attackers to use the privileged APIs.