CVE-2026-20519

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01778993; Issue ID: MSV-8898.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 2 mentions (2026-10-05); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-10-05: 2Mentions · 2026-10-06: 110-0510-06
Referenced assets2 URLs
Full discourse3 posts
  • Rıdvan Yağlı@ridvanyagli

    🔴 MediaTek tarafından çok sayıda güvenlik açığı yayınlandı. CVE-2026-20519 ve CVE-2026-20520 kritik seviyede olup modem bileşenlerinde OOB Write üzerinden uzaktan yetki yükseltmeye yol açabiliyor. CVE-2026-20521–20527, CVE-2026-20586 ve CVE-2026-20589 ise yüksek seviyeli bellek güvenlik açıkları içeriyor. https://www.mediatek.com/product-security-bulletin/october-2026

    00002193
    2.4K followersView on X
  • Yash Rathore@TweetToYash

    Samsung's October 2026 security patch Nine critical-rated Android vulnerabilities are covered, headlined by CVE-2026-20519 and CVE-2026-20520, alongside 33 high-severity fixes and three moderate ones. Nothing in the low category this time.

    0001071
    447 followersView on X
  • Daily CyberSecurity@Daily_CyberSec

    MediaTek security bulletin for October 2026 fixes 31 flaws, including critical MediaTek modem vulnerability CVE-2026-20519. Update now. #MediaTek #Android #ModemSecurity #CVE202620519 #CVE202620520 #MobileSecurity #PatchTuesday #Vulnerability https://securityonline.info/mediatek-security-bulletin-october-2026/

    00010356
    13.0K followersView on X

Explore more