CVE-2026-84696

Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mechanisms. Attackers can bypass the weak CRC-16 based unlock handshake or exploit builds with no VUC lock to read and write controller memory and raw flash, persisting implants across power cycles.

  • Published Sep 2, 2026
  • CVSS 9.3 critical
  • 0.2% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-84696 at the National Vulnerability Database