CVE-2026-50227
- EPSS 0.35%
- Veröffentlicht 23.09.2026 07:15:36
- Zuletzt bearbeitet 25.09.2026 13:15:28
An unauthenticated local attacker can connect to the MQTT broker over its localhost WebSocket endpoint in Acer NitroSense software (versions up to and including 5.2.62). This allows the attacker to invoke exposed ddsc RPC functions, including child_p...
CVE-2026-50604
- EPSS 0.14%
- Veröffentlicht 17.09.2026 04:06:40
- Zuletzt bearbeitet 18.09.2026 16:25:08
A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The socket handshake process does not properly require authentication before granting access to the service. Under certain circumstanc...
CVE-2026-50603
- EPSS 0.07%
- Veröffentlicht 17.09.2026 04:01:12
- Zuletzt bearbeitet 18.09.2026 16:25:08
A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstances, a local at...
CVE-2026-8069
- EPSS 0.12%
- Veröffentlicht 08.05.2026 05:57:22
- Zuletzt bearbeitet 12.08.2026 15:55:22
PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigured, allowing...