Insyde Software has 2 CVEs on record. 2 were published in the last 90 days. The median CVSS is 8.2 (high).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.2
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
2
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Insyde Software vulnerabilities
CVEs affecting Insyde Software, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-12855High· 8.2Unvalidated memory boundary could result in arbitrary code execution
Unvalidated memory boundary could result in arbitrary code execution. The vulnerability exists in the code developed specifically for HP projects.
▾ TwilightInsyde Software · InsydeH2OEPSS 0.13%via NVD
CVE-2026-6485High· 8.2UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands or startup scripts.
UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands or startup scripts.
▾ TwilightInsyde Software · InsydeH2OEPSS 0.12%via NVD