VulnSea

Samsung has 36 CVEs on record. Disclosure cadence is accelerating: 35 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 35. The median CVSS is 5.6 (medium), with 2 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-787 (9) and CWE-122 (4). Most affected products: android (15), Exynos 1330 firmware (7), Exynos 1280 firmware (5).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.6
Publish → KEV
Last 90 days
35 prev 0

Products

  • android 15
  • Exynos 1330 firmware 7
  • Exynos 1280 firmware 5
  • Exynos 850 firmware 4
  • Exynos 1580 firmware 2
  • Exynos 1080 firmware 1
36
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

Samsung vulnerabilities

CVEs affecting Samsung, newest first. Open any entry for full detail, references, and exploit status.

36 CVEsRSS

CVE-2026-21103Medium· 6.1
1w ago

Path traversal in GalaxyDiagnostics prior to SMR Sep-2026 Release 1 allows physical attackers to access files with system privilege.

Path traversal in GalaxyDiagnostics prior to SMR Sep-2026 Release 1 allows physical attackers to access files with system privilege.

Sunlitsamsung · androidEPSS 0.18%via NVD
CVE-2026-21099Medium· 5.5
1w ago

Improper access control in SettingsProvider prior to SMR Sep-2026 Release 1 allows local attackers to access sensitive information.

Improper access control in SettingsProvider prior to SMR Sep-2026 Release 1 allows local attackers to access sensitive information.

Sunlitsamsung · androidEPSS 0.09%via NVD
CVE-2026-21097Medium· 6.7⚖ disputed
1w ago

Improper authentication in ActivityTaskManagerService prior to SMR Sep-2026 Release 1 allows local privileged attackers to launch arbitrary activity.

Improper authentication in ActivityTaskManagerService prior to SMR Sep-2026 Release 1 allows local privileged attackers to launch arbitrary activity.

Sunlitsamsung · androidEPSS 0.12%via NVD
CVE-2026-21093Medium· 6.7
1w ago

Stack-based buffer overflow in PROCA trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.

Stack-based buffer overflow in PROCA trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.

Sunlitsamsung · androidEPSS 0.09%via NVD
CVE-2026-21092Medium· 5.3⚖ disputed
1w ago

Path traversal in ImsService prior to SMR Sep-2026 Release 1 allows remote attackers to create image files with system server privilege.

Path traversal in ImsService prior to SMR Sep-2026 Release 1 allows remote attackers to create image files with system server privilege.

Sunlitsamsung · androidEPSS 0.32%via NVD
CVE-2025-62817High· 7.5
6mo ago

An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500

An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. A NULL pointer dereference of session->ncp_hdr_buf in __pilot_parsing_ncp() causes a denial of service.

Twilightsamsung · exynos_1280_firmwareEPSS 0.29%via NVD
Samsung vulnerabilities (CVEs) — page 2 · VulnSea