CVE-2026-68955

The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privileges of the user who performed the installation.

  • Published Sep 14, 2026
  • CVSS 8.4 high
  • 0.2% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-68955 at the National Vulnerability Database