CVE-2026-20980Disclosure(samsung / android)

LOWCVSS 6.8 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper input validation in PACM prior to SMR Feb-2026 Release 1 allows physical attacker to execute arbitrary commands.

0.0/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • android

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
android

3 versions affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-04: 2Technical Details · 2026-02-04: 202-04
Signal classification1 categories
Disclosure
2100.0%
Referenced assets3 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-20980 Physical Command Injection in PACM Prior to SMR Feb-2026 Release ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-20980 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    A tweet announces CVE‑2026‑20980, a physical command injection flaw in PACM before the Feb‑2026 SMR release, linking to a Vulmon vulnerability page, with no PoC, exploit code, patch info, or evidence of active exploitation.

    0000043
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-20980 Improper input validation in PACM prior to SMR Feb-2026 Release 1 allows physical attacker to execute arbitrary commands. https://www.cve.org/CVERecord?id=CVE-2026-20980

    Post summary

    The statement identifies a new vulnerability (CVE‑2026‑20980) involving improper input validation leading to arbitrary command execution, but provides no PoC, exploit code, active exploitation evidence, or patch information.

    00000189
    56.5K followersView on X
CPE platform detail73 entries

73 of 73 entries

PartVendorProductVersionTarget SWTarget HW
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid15.0--
OSsamsungandroid15.0--
OSsamsungandroid15.0--
OSsamsungandroid15.0--
OSsamsungandroid15.0--
OSsamsungandroid15.0--
OSsamsungandroid15.0--
OSsamsungandroid15.0--
OSsamsungandroid15.0--
OSsamsungandroid15.0--
OSsamsungandroid15.0--
OSsamsungandroid15.0--
OSsamsungandroid15.0--
OSsamsungandroid15.0--
OSsamsungandroid16.0--
OSsamsungandroid16.0--
OSsamsungandroid16.0--
OSsamsungandroid16.0--
OSsamsungandroid16.0--
OSsamsungandroid16.0--
OSsamsungandroid16.0--

Explore more