SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-84696

HIGH · CVSS 8.2 EPSS 0.15% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Firmware versions of the Phison PS3111-S11 controller are vulnerable due to the exposure of privileged vendor unique commands over the ATA interface, lacking adequate authentication. This flaw allows attackers to bypass the weak CRC-16 unlock handshake, enabling them to read and write controller memory and raw flash, which could lead to persistent implants. Organizations using affected firmware should prioritize remediation to protect against potential exploitation and data compromise.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-84696
Severity
HIGH
CVSS
8.2
EPSS
0.15%

Original NVD Description

Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mechanisms. Attackers can bypass the weak CRC-16 based unlock handshake or exploit builds with no VUC lock to read and write controller memory and raw flash, persisting implants across power cycles.