CVE-2026-9489Active Exploitation

LOWCVSS 8.5 · HIGH

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigured, allowing any authenticated local user to execute arbitrary code with NT AUTHORITY\SYSTEM privileges and to delete arbitrary files with SYSTEM privileges. By leveraging this, an attacker can execute arbitrary code on the target system with elevated privileges.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-269CWE-284CWE-732

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-25: 2Active Exploitation · 2026-05-25: 105-25
Signal classification2 categories
Active Exploitation
150.0%
Disclosure
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in Acer NitrorSense (CVE-2026-9489) https://vuldb.com/vuln/365471

    Post summary

    A new high‑critical CVE‑2026‑9489 affecting Acer NitrorSense has been announced; the brief post provides no details on exploitation techniques or mitigation.

    0000090
    2.2K followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    A lot of offensive activities were identified targeting Acer NitrorSense (CVE-2026-9489) https://vuldb.com/vuln/365471/cti

    Post summary

    The post reports widespread offensive activity targeting Acer NitrorSense CVE-2026-9489, but offers no technical or patch information.

    0000077
    2.2K followersView on X

Explore more