CVE-2026-15419

In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to corrupt kernel pool memory, resulting in arbitrary code execution with escalated privileges.

  • Published Sep 10, 2026
  • CVSS 7.0 high
  • 0.2% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-15419 at the National Vulnerability Database