CVE-2026-20980
Improper input validation in PACM prior to SMR Feb-2026 Release 1 allows physical attacker to execute arbitrary commands.
- Samsung Android
- = 14.0, 15.0, 16.0
- CVSS 4.0
- 7.0 HIGH
- CVSS 3.1
- 6.8 MEDIUM
- EPSS
- 0.2% (15th percentile)
- NVD status
- Analyzed
- Published
- 2026-02-04
CVE-2026-20980 at NVD
2 known exploits for CVE-2026-20980
Proof-of-concept code and exploit modules indexed by Sploitus