VulnSea

Lenovo has 19 CVEs on record. Disclosure cadence is accelerating: 8 in the last 90 days against 5 in the 90 before. The busiest recent month was March 2026 with 6. The median CVSS is 7.1 (high), with 1 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-59 (3). Most affected products: dock_manager (3), filez (3), software_fix (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.1
Publish → KEV
Last 90 days
8 prev 5

Products

  • dock_manager 3
  • filez 3
  • software_fix 3
  • smart_connect 2
  • File Manager Application 1
  • FileZ Client 1
19
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

Lenovo vulnerabilities

CVEs affecting Lenovo, newest first. Open any entry for full detail, references, and exploit status.

19 CVEsRSS

CVE-2026-63427High· 7.8
1w ago

An authentication bypass vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.

An authentication bypass vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.

TwilightLenovo · Software FixEPSS 0.14%via NVD
CVE-2026-11813High· 7.8
1w ago

A potential improper permissions vulnerability was reported in the Lenovo Filez Client application that could allow a local authenticated user to escalate privileges.

A potential improper permissions vulnerability was reported in the Lenovo Filez Client application that could allow a local authenticated user to escalate privileges.

TwilightLenovo · FileZ ClientEPSS 0.10%via NVD
CVE-2026-75940Critical· 9.1
1w ago

A vulnerability was reported in Lenovo Health Android Application, distributed exclusively in the Chinese market, that could allow an attacker to access sensitive health-related information.

A vulnerability was reported in Lenovo Health Android Application, distributed exclusively in the Chinese market, that could allow an attacker to access sensitive health-related information.

MidnightLenovo · Health ApplicationEPSS 0.29%via NVD
CVE-2026-19136High· 7.8
1w ago

A potential command injection vulnerability was reported in the Tianxi AI Agent PC Application, distributed exclusively in the Chinese market, that could allow operating system commands to be executed if a local user opens a specially cr…

A potential command injection vulnerability was reported in the Tianxi AI Agent PC Application, distributed exclusively in the Chinese market, that could allow operating system commands to be executed if a local user opens a specially cr…

TwilightLenovo · Tianxi AI Agent PC ApplicationEPSS 0.87%via NVD
CVE-2026-18994High· 7.1
1w ago

A potential improper authorization vulnerability was reported in the Lenovo File Manager Android Application, distributed exclusively in the Chinese market, that could allow a local authenticated user to read or modify protected files wi…

A potential improper authorization vulnerability was reported in the Lenovo File Manager Android Application, distributed exclusively in the Chinese market, that could allow a local authenticated user to read or modify protected files wi…

TwilightLenovo · File Manager ApplicationEPSS 0.10%via NVD
CVE-2026-63426High· 7.1
1mo ago

During an internal security assessment, a potential vulnerability was discovered in Lenovo Dock Manager that could allow an authenticated local user to perform an arbitrary file deletion with elevated privileges.

During an internal security assessment, a potential vulnerability was discovered in Lenovo Dock Manager that could allow an authenticated local user to perform an arbitrary file deletion with elevated privileges.

Twilightlenovo · dock_managerEPSS 0.13%via NVD
CVE-2026-63425High· 7.8
1mo ago

During an internal security assessment, a potential improper permissions vulnerability was discovered in Lenovo Dock Manager that could allow a local authenticated user to execute arbitrary code with elevated privileges.

During an internal security assessment, a potential improper permissions vulnerability was discovered in Lenovo Dock Manager that could allow a local authenticated user to execute arbitrary code with elevated privileges.

Twilightlenovo · dock_managerEPSS 0.11%via NVD
CVE-2026-63424High· 7.3
1mo ago

During an internal security assessment, an improperly protected key was discovered in Lenovo Dock Manager that could allow a local authenticated user to escalate privileges.

During an internal security assessment, an improperly protected key was discovered in Lenovo Dock Manager that could allow a local authenticated user to escalate privileges.

Twilightlenovo · dock_managerEPSS 0.10%via NVD
CVE-2026-4145High· 7.8
5mo ago

During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.

During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.

Twilightlenovo · software_fixEPSS 0.20%via NVD
CVE-2026-4135Medium· 6.6
5mo ago

During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to perform an arbitrary file write with elevated privileges.

During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to perform an arbitrary file write with elevated privileges.

Sunlitlenovo · software_fixEPSS 0.12%via NVD
CVE-2026-4134High· 7.3
5mo ago

During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to execute code with elevated privileges.

During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to execute code with elevated privileges.

Twilightlenovo · software_fixEPSS 0.11%via NVD
CVE-2026-1636Medium· 6.7
5mo ago

A potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allow a local authenticated user to execute code with elevated privileges.

A potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allow a local authenticated user to execute code with elevated privileges.

Sunlitlenovo · service_bridgeEPSS 0.13%via NVD
CVE-2026-0827High· 7.1PoC
5mo ago

During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareScanAddin used in Lenovo Vantage that, during installation or when using hardware scan, could allow a local authentica…

During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareScanAddin used in Lenovo Vantage that, during installation or when using hardware scan, could allow a local authentica…

Midnightlenovo · diagnosticsEPSS 0.21%via NVD
CVE-2026-2640Medium· 5.5
6mo ago

During an internal security assessment, a potential vulnerability was discovered in Lenovo PC Manager that could allow a local authenticated user to terminate privileged processes.

During an internal security assessment, a potential vulnerability was discovered in Lenovo PC Manager that could allow a local authenticated user to terminate privileged processes.

Sunlitlenovo · pcmanagerEPSS 0.11%via NVD
CVE-2026-2368High· 7.1
6mo ago

An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to execute arbitrary code.

An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to execute arbitrary code.

Twilightlenovo · filezEPSS 0.13%via NVD
CVE-2026-1653Medium· 5.5
6mo ago

A potential divide by zero vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could allow a local authenticated user to cause a Windows blue screen error.

A potential divide by zero vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could allow a local authenticated user to cause a Windows blue screen error.

Sunlitlenovo · smart_connectEPSS 0.09%via NVD
CVE-2026-1652Medium· 6.1
6mo ago

A potential buffer overflow vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could allow a local authenticated user to corrupt memory and cause a Windows blue screen error.

A potential buffer overflow vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could allow a local authenticated user to corrupt memory and cause a Windows blue screen error.

Sunlitlenovo · smart_connectEPSS 0.09%via NVD
CVE-2026-1068Medium· 5.3
6mo ago

An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to obtain sensitive user data from the application.

An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to obtain sensitive user data from the application.

Sunlitlenovo · filezEPSS 0.08%via NVD
CVE-2026-0520Low· 2.8
6mo ago

A potential vulnerability was reported in the Lenovo FileZ Android application that, under certain conditions, could allow a local authenticated user to retrieve some sensitive data stored in a log file.

A potential vulnerability was reported in the Lenovo FileZ Android application that, under certain conditions, could allow a local authenticated user to retrieve some sensitive data stored in a log file.

Sunlitlenovo · filezEPSS 0.09%via NVD
Lenovo vulnerabilities (CVEs) · VulnSea