Junglewise Threat Intelligence

CVE-2026-10587: Lenovo BIOS out-of-bounds write in System Management Mode

CVE-2026-10587 · Severity: medium · CVSS 6 · Published 2026-07-16

Technologies: Lenovo Legion Pro 7 16AFR10H BIOS, Lenovo Legion Pro 5 16ADR10 BIOS, Lenovo LOQ 15ARP10E BIOS, Lenovo Yoga Book 9 14IAH10 BIOS, Lenovo Legion Pro 5 16AFR10 BIOS, Lenovo IdeaPad Pro 5 16IPH11 BIOS, Lenovo V15 G6 ARP BIOS, Lenovo Legion Pro 7 16ADR10H BIOS, Lenovo Legion 7 16AGP11 BIOS, Lenovo IdeaPad Pro 5 16AGP11 BIOS, Lenovo Yoga Pro 7 15IPH11 BIOS. Vendors: Lenovo.

Executive brief

A vulnerability in the BIOS firmware of several Lenovo laptop models could allow an attacker with administrative access to the computer to modify highly sensitive power management settings. These settings are handled in a protected area of the system called System Management Mode (SMM). If exploited, this could lead to system instability or a denial of service by tampering with how the hardware manages power and performance.

Technical details

An out-of-bounds write vulnerability exists within the System Management Mode (SMM) of various Lenovo BIOS versions. A local attacker with high privileges (administrative or SYSTEM) can trigger this flaw to write data outside of intended memory boundaries. This specific vulnerability targets power management configurations handled by SMM. Successful exploitation allows the attacker to modify these settings, potentially leading to a denial of service or unauthorized modification of firmware-level parameters. Fixes are available via BIOS updates for the affected models.

Affected products

  • Lenovo Yoga Pro 7 15IPH11 BIOS before TNCN37WW
  • Lenovo IdeaPad Pro 5 16IPH11 BIOS before S4CN62WW
  • Lenovo Legion 7 16AGP11 BIOS up to and including TPCN27WW
  • Lenovo IdeaPad Pro 5 16AGP11 BIOS up to and including T8CN19WW
  • Lenovo Legion Pro 5 16ADR10 BIOS up to and including U5CN07WW
  • Lenovo Lenovo V15 G6 ARP BIOS up to and including TYCN15WW
  • Lenovo LOQ 15ARP10E BIOS before SUCN18WW
  • Lenovo Yoga Book 9 14IAH10 BIOS up to and including QEME23WW
  • Lenovo Legion Pro 7 16AFR10H BIOS before SMCN20WW
  • Lenovo Legion Pro 5 16AFR10 BIOS up to and including RECN14WW
  • Lenovo Legion Pro 7 16ADR10H BIOS before SJCN17WW

Timeline

  • 2026-07-16: disclosed
  • 2026-07-16: advisory

References

Related threats