SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-90508

LOW · CVSS 3.4 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-13 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

A vulnerability exists in the MessageNotifyCallback function of the ProtectFilter64.sys library within Chengdu Qilu Technology's Ludashi 6.1026.4715.714, allowing for unauthorized access when manipulated. This flaw requires local exploitation, posing a risk primarily to systems running the affected software. Organizations using this product should prioritize remediation due to the public availability of the exploit.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-90508
Severity
LOW
CVSS
3.4
EPSS
N/A

Original NVD Description

A security flaw has been discovered in Chengdu Qilu Technology Ludashi 6.1026.4715.714. Affected by this vulnerability is the function MessageNotifyCallback in the library ProtectFilter64.sys of the component Message Dispatch Handler. Performing a manipulation results in missing authorization. Attacking locally is a requirement. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.