CVE-2026-2999Disclosure(changingtec / idexpert)

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch changingtec idexpert systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary executable files from a remote source and execute them.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-494

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • idexpert

Threat summary

  • Patch or workaround signal is available
  • 11 mentions across 5 observed days
  • Momentum state: declining

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 10 signals
  • Disclosure: 10 classified signals
  • Peaked 4d ago at 7 mentions (2026-03-02); latest day: 1
  • 11 total mentions across 5 days

Affected systems

Products
idexpert

Deep dive

Activity timeline11 mentions / 5d
02457Mentions · 2026-03-02: 7Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Mentions · 2026-03-07: 1Mentions · 2026-03-09: 1Patch / Workaround · 2026-03-02: 1Technical Details · 2026-03-02: 6Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-07: 1Technical Details · 2026-03-09: 103-0203-0503-0603-0703-09
Signal classification2 categories
Disclosure
1090.9%
Patch
19.1%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-03-027
Disclosure6Patch1
2026-03-051
Disclosure1
2026-03-061
Disclosure1
2026-03-071
Disclosure1
2026-03-091
Disclosure1
Full discourse11 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-2999 IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download … https://www.cve.org/CVERecord?id=CVE-2026-2999

    Post summary

    The post announces a remote code execution vulnerability in IDExpert Windows Logon Agent, noting that unauthenticated attackers can force the system to download malicious code.

    00010523
    56.6K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Changing IDExpert Logon Agent, Remote Code Execution, #CVE-2026-2999 (CRITICAL) https://dailycve.com/changing-idexpert-logon-agent-remote-code-execution-cve-2026-2999-critical/

    Post summary

    A new remote code execution vulnerability, CVE‑2026‑2999, has been disclosed for IDExpert Logon Agent with a critical severity rating; the tweet offers no evidence of existing exploit code, active exploitation, or patch availability.

    0000037
    166 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-2999 (CVSS:9.3, CRITICAL) is Undergoing Analysis. IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated r..https://nvd.nist.gov/vuln/detail/CVE-2026-2999 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces a critical RCE vulnerability (CVE-2026-2999) in IDExpert Windows Logon Agent, noting its CVSS score and that analysis is underway, with no PoC, exploit, or patch information.

    0000024
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-2999 (CVSS:9.3, CRITICAL) is Undergoing Analysis. IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated r..https://nvd.nist.gov/vuln/detail/CVE-2026-2999 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-2999, a critical RCE vulnerability in IDExpert Windows Logon Agent, providing CVSS details but lacking any PoC, exploit code, or patch information.

    0000024
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-2999 (CVSS:9.3, CRITICAL) is Awaiting Analysis. IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated r..https://nvd.nist.gov/vuln/detail/CVE-2026-2999 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces the discovery of CVE-2026-2999, a high‑severity remote code execution flaw in IDExpert Windows Logon Agent, and awaits further analysis.

    0000021
    173 followersView on X
  • The AI generalist@AIengineerlife
    Patch

    🚨 CVE-2026-2999 - CRITICAL IDExpert Windows Logon Agent 🤖 AI Summary: Critical RCE allows unauthenticated remote code execution. Patch immediately. ThreatScore: 95/100 🔗 http://threatmonitor.io/cve/CVE-2026-2999 #cybersecurity #infosec #CVE

    Post summary

    CVE-2026-2999 is a critical remote code execution vulnerability in IDExpert Windows Logon Agent; immediate patching is advised.

    0000061
    8 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-2999 Remote Code Execution in IDExpert Windows Logon Agent via Arbitrar... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2999 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    A new CVE-2026-2999 vulnerability is disclosed, describing a remote code execution flaw in the IDExpert Windows Logon Agent.

    0000054
    4.0K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    The severity is increased for this new vulnerability affecting Changing IDExpert Windows Logon Agent (CVE-2026-2999) https://vuldb.com/?id.348309

    Post summary

    The post announces that the severity rating for CVE-2026-2999, a vulnerability in Changing IDExpert Windows Logon Agent, has been increased.

    0000086
    2.1K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-2999: CRITICAL] Critical security alert: IDExpert Windows Logon Agent by Changing has a Remote Code Execution vulnerability. Remote attackers can force system to download and execute files.#cve,CVE-2026-2999,#cybersecurity https://cvefind.com/CVE-2026-2999

    Post summary

    A critical remote code execution vulnerability (CVE‑2026‑2999) in IDExpert Windows Logon Agent is announced, allowing attackers to force the system to download and execute files.

    0000068
    590 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-2999 - Critical IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary executable... https://www.thehackerwire.com/vulnerability/CVE-2026-2999/ https://t.co/7xuCz1UH8K

    Post summary

    A new critical RCE vulnerability (CVE-2026-2999) in IDExpert Windows Logon Agent allows unauthenticated attackers to download arbitrary executables.

    0000064
    122 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-2999 IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download … https://www.cve.org/CVERecord?id=CVE-2026-2999 ----- Traducción: CVE-2026-2999 IDE… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-2999, a remote code execution flaw in IDExpert Windows Logon Agent, noting that unauthenticated remote attackers can force the system to download malicious content.

    0000036
    55 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appchangingtecidexpert-windows-

Explore more