lenovo
Latest CVEs
The 15 most recently published vulnerabilities affecting lenovo.
- CVE-2026-14256ELAN reported a potential out-of-bounds write vulnerability in the ELAN TrackPoint driver that, under certain circumstances, could allow a local authenticated user to cause a system crash.4.7
- CVE-2026-15994During an internal security assessment, an improper link following vulnerability was identified in Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to execut...7.0
- CVE-2026-63423During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a local authenticated user to ...7.8
- CVE-2026-63424During an internal security assessment, an improperly protected key was discovered in Lenovo Dock Manager that could allow a local authenticated user to escalate privileges.7.3
- CVE-2026-63425During an internal security assessment, a potential improper permissions vulnerability was discovered in Lenovo Dock Manager that could allow a local authenticated user to execute arbitrary code wi...7.8
- CVE-2026-63426During an internal security assessment, a potential vulnerability was discovered in Lenovo Dock Manager that could allow an authenticated local user to perform an arbitrary file deletion with eleva...7.1
- CVE-2026-12036An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to perform an arbitrary fi...7.1
- CVE-2026-6387A potential authentication bypass vulnerability was reported in Lenovo System Update that could allow a local authenticated user to execute arbitrary code with elevated privileges.7.0
- CVE-2026-16793Remote Command Injection via OS Profile Password in Lenovo XClarity Orchestrator8.8
- CVE-2026-16792Global TLS Certificate Validation Bypass in Lenovo XClarity Orchestrator6.1
- CVE-2026-16791Predictable Temporary File Symlink Vulnerability in Lenovo XClarity Essentials OneCLI3.9
- CVE-2026-10590A potential missing authentication vulnerability could allow a local privileged attacker to use WMI commands to arbitrarily trigger a System Management Interrupt handler.4.4
- CVE-2026-10589A potential out of bounds write vulnerability could allow a local privileged attacker to execute code in System Management Mode.6.0
- CVE-2026-10588A potential vulnerability could allow a local privileged attacker to disclose the address of protected System Management Mode memory.4.4
- CVE-2026-10587A potential out-of-bounds write vulnerability could allow a local privileged attacker to modify power management settings in System Management Mode.6.0