CVE-2026-30612

An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <= 3.5.0.173 allows a remote attacker to execute arbitrary code via the updater.exe for windows, PT.updd on MacOS components

  • Published Aug 27, 2026
  • CVSS 9.8 critical
  • 0.4% chance of exploitation in the next 30 days (EPSS)

CVE-2026-30612 at the National Vulnerability Database