
CVE-2026-20981 Improper input validation in FacAtFunction prior to SMR Feb-2026 Release 1 allows privileged physical attacker to execute arbitrary command with system privilege. https://www.cve.org/CVERecord?id=CVE-2026-20981
Post summary
The statement discloses CVE‑2026‑20981, describing an improper input validation that allows privileged physical attackers to execute arbitrary commands with system privilege, but provides no PoC, exploit code, or patch details.

