CVE-2026-90508

A security flaw has been discovered in Chengdu Qilu Technology Ludashi 6.1026.4715.714. Affected by this vulnerability is the function MessageNotifyCallback in the library ProtectFilter64.sys of the component Message Dispatch Handler. Performing a manipulation results in missing authorization. Attacking locally is a requirement. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

  • Published Sep 13, 2026
  • CVSS 1.8 low
  • 0.2% chance of exploitation in the next 30 days (EPSS)
  • No fix is known yet

Affected software

CVE-2026-90508 at the National Vulnerability Database