Sploitus

CVE-2026-20981

2 known exploits for CVE-2026-20981

Improper input validation in FacAtFunction prior to SMR Feb-2026 Release 1 allows privileged physical attacker to execute arbitrary command with system privilege.

Samsung Android
= 14.0, 15.0, 16.0
CVSS 3.1
6.6 MEDIUM
EPSS
0.2% (10th percentile)
NVD status
Analyzed
Published
2026-02-04
CVE-2026-20981 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2026-20981

Proof-of-concept code and exploit modules indexed by Sploitus