SEPTEMBER 1, 2026
Live Feed
Back to database
Case File

CVE-2026-6851

HIGH · CVSS 7 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

A vulnerability in the File Shredder module of Bitdefender Total Security and Internet Security on Windows allows local users with limited privileges to exploit race conditions through symbolic links, potentially leading to unauthorized privilege escalation. Users of affected versions (prior to 27.0.58.315) should prioritize immediate updates to mitigate the risk of exploitation. Organizations relying on these Bitdefender products should assess their security posture and apply necessary patches to safeguard against potential attacks.

CVE
CVE-2026-6851
Severity
HIGH
CVSS
7
EPSS
0.12%
Windows

Original NVD Description

An Improper link resolution before file access ('link following') vulnerability in the File Shredder module as used in Bitdefender Total Security and Internet Security on Windows allows a less-privileged local user to elevate rights by leveraging a race conditions via Symbolic Links. This issue affects Total Security: before 27.0.58.315; Internet Security: before 27.0.58.315.

Related CVEs

Other vulnerabilities affecting the same vendor(s)