SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-30612

CRITICAL · CVSS 9.8 EPSS 0.31% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Time4 Popcorn applications for Windows, MacOS, and Android are vulnerable to remote code execution due to flaws in their updater components. Attackers can exploit these vulnerabilities to execute arbitrary code on affected systems, potentially compromising user data and system integrity. Users and organizations utilizing these applications should prioritize immediate updates to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-30612
Severity
CRITICAL
CVSS
9.8
EPSS
0.31%
Windows Android

Original NVD Description

An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <= 3.5.0.173 allows a remote attacker to execute arbitrary code via the updater.exe for windows, PT.updd on MacOS components