CVE-2026-63427

An authentication bypass vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.

  • Published Sep 10, 2026
  • CVSS 8.5 high
  • 0.2% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-63427 at the National Vulnerability Database