CVE-2026-12780Disclosure

LOW

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

1.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-06-21); latest day: 1
  • 6 total mentions across 4 days

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-06-20: 1Mentions · 2026-06-21: 2Mentions · 2026-06-22: 2Mentions · 2026-09-14: 1PoC Mentioned / Linked · 2026-06-22: 2Technical Details · 2026-06-21: 2Technical Details · 2026-06-22: 206-2006-2106-2209-14
Signal classification2 categories
Disclosure
360.0%
PoC
240.0%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-06-201
Disclosure1
2026-06-212
Disclosure2
2026-06-222
PoC2
Full discourse6 posts
  • Winslow@senzee1984
    Disclosure

    Utilized LLM and discovered kernel drivers' vulnerabilities, 8 of them are already credited, all of them are LPE vulnerabilities: CVE-2026-12217, CVE-2026-12778, CVE-2026-12779, CVE-2026-12780, CVE-2026-12781, CVE-2026-12782, CVE-2026-12784, CVE-2026-12786

    Post summary

    The message reports that an LLM was used to identify eight kernel driver local privilege escalation vulnerabilities (CVE-2026-12217, 2026-12778 to 2026-12786), but it provides no PoC, exploit code, active exploitation evidence, or patch details.

    140843911.5K
    1.8K followersView on X
  • CSIRT Italia@csirt_it
    PoC

    #Aomei: disponibili #PoC per lo sfruttamento delle CVE-2026-12778, CVE-2026-12779 e CVE-2026-12780 Rischio: 🟠 Tipologia: 🔸 Elevation of Privilege 🔸 Data Manipulation 🔗 https://www.acn.gov.it/portale/w/aomei-disponibili-poc-pubblici-per-le-cve-2026-12778-cve-2026-12779-e-cve-2026-12780 ⚠ Monitorare il sito del vendor https://t.co/AgmlKeKyEd

    Post summary

    A PoC for the Aomei CVEs 2026‑12778, 12779 and 12780 has been made publicly available, indicating potential elevation of privilege and data manipulation risks, with no mention of active exploitation, patches, or false positives.

    00041772
    9.0K followersView on X
  • CVE Official@CVE2026COIN
    Disclosure

    🟠 HIGH (CVSS 7.8) — CVE-2026-12780 Published: 2026-06-21 A vulnerability was determined in AOMEI Backupper up to 8.3.0. Impacted is an unknown function in the library amwrtdrv.sys of the component Kernel Driver. Executing a manipulation can lead to improper access controls. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. 🧬 CVSS 3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 🔗 NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-12780 📚 References: • https://vuldb.com/cve/CVE-2026-12780 • https://vuldb.com/submit/835609 • https://vuldb.com/vuln/372521 • https://vuldb.com/vuln/372521/cti #CVE #CyberSecurity #InfoSec #Vulnerability

    Post summary

    The post announces CVE-2026-12780, a local privilege escalation in AOMEI Backupper’s kernel driver, detailing its CVSS score and exploitability but without PoC, tool, or patch information.

    00040141
    21 followersView on X
  • NEXSIGHT@NEXSIGHTNEWS

    AOMEI Backupperのカーネルドライバ「amwrtdrv.sys」に権限昇格の脆弱性 — CERT/CCが注意喚起、Secure Boot無効のPCでは攻撃者にEDRを回避されUEFI段階でコードを実行されるおそれ https://cyber.nexsight.co/articles/2026/09/14/aomei-backupper-amwrtdrv-sys-lpe-uefi-cve-2026-12780-2026-09-14/

    0000052
    70 followersView on X
  • Hephaestvs@Vulcanux_
    PoC

    csirt_it: ‼ #Aomei: disponibili #PoC per lo sfruttamento delle CVE-2026-12778, CVE-2026-12779 e CVE-2026-12780 Rischio: 🟠 Tipologia: 🔸 Elevation of Privilege 🔸 Data Manipulation 🔗 https://www.acn.gov.it/portale/w/aomei-disponibili-poc-pubblici-per-le-cve-2026-12778-cve-2026-12779-e-cve-2026-12780 ⚠ Monitorare il sito del vendor https://t.co/8mgSyYzo49

    Post summary

    The tweet announces that publicly available PoCs exist for three CVEs involving privilege escalation and data manipulation, but it does not discuss patches or active exploitation.

    0000048
    620 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-12780 Improper Access Control in AOMEI Backupper Kernel Driver amwrtdrv.sys https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-12780 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The entry announces CVE-2026-12780, detailing an improper access control flaw in the AOMEI Backupper kernel driver amwrtdrv.sys, and links to official vulnerability information.

    0000058
    4.1K followersView on X

Explore more