{"schema_version":1,"title":"Lenovo vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 31 vulnerabilities in Lenovo: 0 in the last 7 days and 16 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-75940, was published on 10 September 2026. 11 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/lenovo","json_url":"https://junglewise.ai/threats/vendors/lenovo.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/lenovo","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":15,"all_time":31,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":4,"last_90_days":16,"last_365_days":28},"latest":[{"cve":"CVE-2026-75940","cvss":9.1,"epss":0.004,"slug":"cve-2026-75940-lenovo-health-android-application-information-disclosure","title":"Lenovo Health Android Application information disclosure vulnerability","severity":"critical","exploited":false,"published_at":"2026-09-10T21:17:44.08+00:00","url":"https://junglewise.ai/threats/cve-2026-75940-lenovo-health-android-application-information-disclosure"},{"cve":"CVE-2026-63427","cvss":7.8,"epss":0.0019,"slug":"cve-2026-63427-lenovo-software-fix-authentication-bypass","title":"Lenovo Software Fix authentication bypass","severity":"high","exploited":false,"published_at":"2026-09-10T21:17:28.347+00:00","url":"https://junglewise.ai/threats/cve-2026-63427-lenovo-software-fix-authentication-bypass"},{"cve":"CVE-2026-19136","cvss":7.8,"epss":0.0087,"slug":"cve-2026-19136-tianxi-ai-agent-pc-application-command-injection","title":"Tianxi AI Agent PC Application command injection","severity":"high","exploited":false,"published_at":"2026-09-10T21:17:24.613+00:00","url":"https://junglewise.ai/threats/cve-2026-19136-tianxi-ai-agent-pc-application-command-injection"},{"cve":"CVE-2026-11813","cvss":7.8,"epss":0.001,"slug":"cve-2026-11813-lenovo-filez-client-privilege-escalation-via-improper-permissions","title":"Lenovo Filez Client privilege escalation via improper permissions","severity":"high","exploited":false,"published_at":"2026-09-10T21:17:18.357+00:00","url":"https://junglewise.ai/threats/cve-2026-11813-lenovo-filez-client-privilege-escalation-via-improper-permissions"},{"cve":"CVE-2026-16793","cvss":8.8,"epss":0.0052,"slug":"cve-2026-16793-lenovo-xclarity-orchestrator-command-injection-vulnerability","title":"Lenovo XClarity Orchestrator command injection vulnerability","severity":"high","exploited":false,"published_at":"2026-08-04T20:16:49.463+00:00","url":"https://junglewise.ai/threats/cve-2026-16793-lenovo-xclarity-orchestrator-command-injection-vulnerability"},{"cve":"CVE-2026-16792","cvss":6.1,"epss":0.0011,"slug":"cve-2026-16792-lenovo-xclarity-orchestrator-improper-certificate-validation-in","title":"Lenovo XClarity Orchestrator improper certificate validation in microservices","severity":"medium","exploited":false,"published_at":"2026-08-04T20:16:49.317+00:00","url":"https://junglewise.ai/threats/cve-2026-16792-lenovo-xclarity-orchestrator-improper-certificate-validation-in"},{"cve":"CVE-2026-16791","cvss":3.9,"epss":0.0013,"slug":"cve-2026-16791-lenovo-xclarity-essentials-onecli-temporary-file-overwrite","title":"Lenovo XClarity Essentials OneCLI temporary file overwrite","severity":"low","exploited":false,"published_at":"2026-08-04T20:16:49.13+00:00","url":"https://junglewise.ai/threats/cve-2026-16791-lenovo-xclarity-essentials-onecli-temporary-file-overwrite"},{"cve":"CVE-2026-9046","cvss":7,"slug":"cve-2026-9046-lenovo-legion-zone-and-app-store-insecure-permissions-in-windows","title":"Lenovo Legion Zone and App Store insecure permissions in Windows applications","severity":"high","exploited":false,"published_at":"2026-07-16T17:16:59.1+00:00","url":"https://junglewise.ai/threats/cve-2026-9046-lenovo-legion-zone-and-app-store-insecure-permissions-in-windows"},{"cve":"CVE-2026-6511","cvss":5.5,"slug":"cve-2026-6511-lenovo-smart-connect-improper-access-control-in-windows","title":"Lenovo Smart Connect improper access control in Windows","severity":"medium","exploited":false,"published_at":"2026-07-16T17:16:58.97+00:00","url":"https://junglewise.ai/threats/cve-2026-6511-lenovo-smart-connect-improper-access-control-in-windows"},{"cve":"CVE-2026-14371","cvss":8.8,"slug":"cve-2026-14371-lenovo-xclarity-integrator-powershell-command-injection-in-wac","title":"Lenovo XClarity Integrator PowerShell command injection in WAC Gateway","severity":"info","exploited":false,"published_at":"2026-07-16T17:16:55.423+00:00","url":"https://junglewise.ai/threats/cve-2026-14371-lenovo-xclarity-integrator-powershell-command-injection-in-wac"},{"cve":"CVE-2026-13104","cvss":7.3,"slug":"cve-2026-13104-lenovo-app-store-privilege-escalation-in-chinese-market-version","title":"Lenovo App Store privilege escalation in Chinese market version","severity":"high","exploited":false,"published_at":"2026-07-16T17:16:55.09+00:00","url":"https://junglewise.ai/threats/cve-2026-13104-lenovo-app-store-privilege-escalation-in-chinese-market-version"},{"cve":"CVE-2026-13103","cvss":7.3,"slug":"cve-2026-13103-lenovo-app-store-path-traversal-code-execution","title":"Lenovo App Store path traversal code execution","severity":"high","exploited":false,"published_at":"2026-07-16T17:16:54.95+00:00","url":"https://junglewise.ai/threats/cve-2026-13103-lenovo-app-store-path-traversal-code-execution"},{"cve":"CVE-2026-10590","cvss":4.4,"slug":"cve-2026-10590-lenovo-bios-missing-authentication-in-smi-handler-via-wmi","title":"Lenovo BIOS missing authentication in SMI handler via WMI","severity":"medium","exploited":false,"published_at":"2026-07-16T17:16:54.407+00:00","url":"https://junglewise.ai/threats/cve-2026-10590-lenovo-bios-missing-authentication-in-smi-handler-via-wmi"},{"cve":"CVE-2026-10589","cvss":6,"slug":"cve-2026-10589-lenovo-bios-out-of-bounds-write-in-system-management-mode","title":"Lenovo BIOS out of bounds write in System Management Mode","severity":"medium","exploited":false,"published_at":"2026-07-16T17:16:54.09+00:00","url":"https://junglewise.ai/threats/cve-2026-10589-lenovo-bios-out-of-bounds-write-in-system-management-mode"},{"cve":"CVE-2026-10588","cvss":4.4,"slug":"cve-2026-10588-lenovo-bios-information-disclosure-in-system-management-mode","title":"Lenovo BIOS information disclosure in System Management Mode memory","severity":"medium","exploited":false,"published_at":"2026-07-16T17:16:53.72+00:00","url":"https://junglewise.ai/threats/cve-2026-10588-lenovo-bios-information-disclosure-in-system-management-mode"},{"cve":"CVE-2026-10587","cvss":6,"slug":"cve-2026-10587-lenovo-bios-out-of-bounds-write-in-system-management-mode","title":"Lenovo BIOS out-of-bounds write in System Management Mode","severity":"medium","exploited":false,"published_at":"2026-07-16T17:16:53.3+00:00","url":"https://junglewise.ai/threats/cve-2026-10587-lenovo-bios-out-of-bounds-write-in-system-management-mode"},{"cve":"CVE-2026-9045","cvss":7.8,"slug":"cve-2026-9045-lenovo-accessories-and-display-manager-privilege-escalation","title":"Lenovo Accessories and Display Manager privilege escalation","severity":"high","exploited":false,"published_at":"2026-06-10T15:16:43.07+00:00","url":"https://junglewise.ai/threats/cve-2026-9045-lenovo-accessories-and-display-manager-privilege-escalation"},{"cve":"CVE-2026-8637","cvss":7.8,"slug":"cve-2026-8637-lenovo-lanschool-classic-uncontrolled-search-path-vulnerability","title":"Lenovo LanSchool Classic uncontrolled search path vulnerability","severity":"high","exploited":false,"published_at":"2026-06-10T15:16:42.93+00:00","url":"https://junglewise.ai/threats/cve-2026-8637-lenovo-lanschool-classic-uncontrolled-search-path-vulnerability"},{"cve":"CVE-2026-7516","cvss":4.3,"slug":"cve-2026-7516-lenovo-android-application-clipboard-overwrite-in-built-in-browser","title":"Lenovo Android Application clipboard overwrite in built-in browser","severity":"medium","exploited":false,"published_at":"2026-06-10T15:16:42.657+00:00","url":"https://junglewise.ai/threats/cve-2026-7516-lenovo-android-application-clipboard-overwrite-in-built-in-browser"},{"cve":"CVE-2026-6090","cvss":7,"slug":"cve-2026-6090-lenovo-smart-connect-for-windows-authentication-bypass","title":"Lenovo Smart Connect for Windows authentication bypass","severity":"high","exploited":false,"published_at":"2026-06-10T15:16:42.513+00:00","url":"https://junglewise.ai/threats/cve-2026-6090-lenovo-smart-connect-for-windows-authentication-bypass"},{"cve":"CVE-2025-10238","cvss":6.7,"slug":"cve-2025-10238-lenovo-thinkpad-bios-out-of-bounds-write-in-smm","title":"Lenovo ThinkPad BIOS out-of-bounds write in SMM","severity":"medium","exploited":false,"published_at":"2026-06-10T15:16:31.053+00:00","url":"https://junglewise.ai/threats/cve-2025-10238-lenovo-thinkpad-bios-out-of-bounds-write-in-smm"},{"cve":"CVE-2025-10237","cvss":6.7,"slug":"cve-2025-10237-lenovo-thinkpad-arbitrary-memory-access-in-embedded-controller","title":"Lenovo ThinkPad arbitrary memory access in embedded controller firmware","severity":"medium","exploited":false,"published_at":"2026-06-10T15:16:30.54+00:00","url":"https://junglewise.ai/threats/cve-2025-10237-lenovo-thinkpad-arbitrary-memory-access-in-embedded-controller"},{"cve":"CVE-2026-6282","cvss":8.1,"slug":"cve-2026-6282-lenovo-personal-cloud-storage-path-traversal-in-file-management","title":"Lenovo Personal Cloud Storage path traversal in file management","severity":"high","exploited":false,"published_at":"2026-05-13T16:17:01.96+00:00","url":"https://junglewise.ai/threats/cve-2026-6282-lenovo-personal-cloud-storage-path-traversal-in-file-management"},{"cve":"CVE-2026-6281","cvss":8.8,"slug":"cve-2026-6281-lenovo-personal-cloud-storage-os-command-injection","title":"Lenovo Personal Cloud Storage OS command injection","severity":"high","exploited":false,"published_at":"2026-05-13T16:17:01.773+00:00","url":"https://junglewise.ai/threats/cve-2026-6281-lenovo-personal-cloud-storage-os-command-injection"},{"cve":"CVE-2026-2640","cvss":5.5,"epss":0.0012,"slug":"cve-2026-2640-lenovo-pc-manager-privilege-escalation-via-process-termination","title":"Lenovo PC Manager privilege escalation via process termination","severity":"medium","exploited":false,"published_at":"2026-03-11T21:16:15.687+00:00","url":"https://junglewise.ai/threats/cve-2026-2640-lenovo-pc-manager-privilege-escalation-via-process-termination"}],"vendor":{"hub":true,"name":"Lenovo","slug":"lenovo","homepage":"https://www.lenovo.com/","description":"A multinational technology company that designs, manufactures, and markets consumer electronics, personal computers, and business solutions.","url":"https://junglewise.ai/threats/vendors/lenovo"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":9},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":1,"exploited":0,"vulnerabilities":4},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-75940","cvss":9.1,"epss":0.004,"slug":"cve-2026-75940-lenovo-health-android-application-information-disclosure","title":"Lenovo Health Android Application information disclosure vulnerability","severity":"critical","exploited":false,"published_at":"2026-09-10T21:17:44.08+00:00","url":"https://junglewise.ai/threats/cve-2026-75940-lenovo-health-android-application-information-disclosure"},{"cve":"CVE-2026-16793","cvss":8.8,"epss":0.0052,"slug":"cve-2026-16793-lenovo-xclarity-orchestrator-command-injection-vulnerability","title":"Lenovo XClarity Orchestrator command injection vulnerability","severity":"high","exploited":false,"published_at":"2026-08-04T20:16:49.463+00:00","url":"https://junglewise.ai/threats/cve-2026-16793-lenovo-xclarity-orchestrator-command-injection-vulnerability"},{"cve":"CVE-2026-6281","cvss":8.8,"slug":"cve-2026-6281-lenovo-personal-cloud-storage-os-command-injection","title":"Lenovo Personal Cloud Storage OS command injection","severity":"high","exploited":false,"published_at":"2026-05-13T16:17:01.773+00:00","url":"https://junglewise.ai/threats/cve-2026-6281-lenovo-personal-cloud-storage-os-command-injection"},{"cve":"CVE-2026-6282","cvss":8.1,"slug":"cve-2026-6282-lenovo-personal-cloud-storage-path-traversal-in-file-management","title":"Lenovo Personal Cloud Storage path traversal in file management","severity":"high","exploited":false,"published_at":"2026-05-13T16:17:01.96+00:00","url":"https://junglewise.ai/threats/cve-2026-6282-lenovo-personal-cloud-storage-path-traversal-in-file-management"},{"cve":"CVE-2026-19136","cvss":7.8,"epss":0.0087,"slug":"cve-2026-19136-tianxi-ai-agent-pc-application-command-injection","title":"Tianxi AI Agent PC Application command injection","severity":"high","exploited":false,"published_at":"2026-09-10T21:17:24.613+00:00","url":"https://junglewise.ai/threats/cve-2026-19136-tianxi-ai-agent-pc-application-command-injection"},{"cve":"CVE-2026-63427","cvss":7.8,"epss":0.0019,"slug":"cve-2026-63427-lenovo-software-fix-authentication-bypass","title":"Lenovo Software Fix authentication bypass","severity":"high","exploited":false,"published_at":"2026-09-10T21:17:28.347+00:00","url":"https://junglewise.ai/threats/cve-2026-63427-lenovo-software-fix-authentication-bypass"},{"cve":"CVE-2026-11813","cvss":7.8,"epss":0.001,"slug":"cve-2026-11813-lenovo-filez-client-privilege-escalation-via-improper-permissions","title":"Lenovo Filez Client privilege escalation via improper permissions","severity":"high","exploited":false,"published_at":"2026-09-10T21:17:18.357+00:00","url":"https://junglewise.ai/threats/cve-2026-11813-lenovo-filez-client-privilege-escalation-via-improper-permissions"},{"cve":"CVE-2026-9045","cvss":7.8,"slug":"cve-2026-9045-lenovo-accessories-and-display-manager-privilege-escalation","title":"Lenovo Accessories and Display Manager privilege escalation","severity":"high","exploited":false,"published_at":"2026-06-10T15:16:43.07+00:00","url":"https://junglewise.ai/threats/cve-2026-9045-lenovo-accessories-and-display-manager-privilege-escalation"},{"cve":"CVE-2026-8637","cvss":7.8,"slug":"cve-2026-8637-lenovo-lanschool-classic-uncontrolled-search-path-vulnerability","title":"Lenovo LanSchool Classic uncontrolled search path vulnerability","severity":"high","exploited":false,"published_at":"2026-06-10T15:16:42.93+00:00","url":"https://junglewise.ai/threats/cve-2026-8637-lenovo-lanschool-classic-uncontrolled-search-path-vulnerability"},{"cve":"CVE-2016-8227","cvss":7.8,"slug":"cve-2016-8227-lenovo-transition-privilege-escalation-in-yoga-flex-and-miix","title":"Lenovo Transition privilege escalation in Yoga, Flex, and Miix systems","severity":"high","exploited":false,"published_at":"2017-01-26T17:59:00.21+00:00","url":"https://junglewise.ai/threats/cve-2016-8227-lenovo-transition-privilege-escalation-in-yoga-flex-and-miix"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"name":"Lenovo IdeaPad Pro 5 16AGP11 BIOS","slug":"ideapad-pro-5-16agp11-bios","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/ideapad-pro-5-16agp11-bios"},{"name":"Lenovo IdeaPad Pro 5 16IPH11 BIOS","slug":"ideapad-pro-5-16iph11-bios","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/ideapad-pro-5-16iph11-bios"},{"name":"Lenovo Legion 7 16AGP11 BIOS","slug":"legion-7-16agp11-bios","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/legion-7-16agp11-bios"},{"name":"Lenovo Legion Pro 5 16ADR10 BIOS","slug":"legion-pro-5-16adr10-bios","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/legion-pro-5-16adr10-bios"},{"name":"Lenovo Legion Pro 5 16AFR10 BIOS","slug":"legion-pro-5-16afr10-bios","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/legion-pro-5-16afr10-bios"},{"name":"Lenovo Legion Pro 7 16ADR10H BIOS","slug":"legion-pro-7-16adr10h-bios","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/legion-pro-7-16adr10h-bios"},{"name":"Lenovo Legion Pro 7 16AFR10H BIOS","slug":"legion-pro-7-16afr10h-bios","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/legion-pro-7-16afr10h-bios"},{"name":"Lenovo LOQ 15ARP10E BIOS","slug":"loq-15arp10e-bios","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/loq-15arp10e-bios"},{"name":"Lenovo V15 G6 ARP BIOS","slug":"v15-g6-arp-bios","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/v15-g6-arp-bios"},{"name":"Lenovo Yoga Book 9 14IAH10 BIOS","slug":"yoga-book-9-14iah10-bios","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/yoga-book-9-14iah10-bios"},{"name":"Lenovo Yoga Pro 7 15IPH11 BIOS","slug":"yoga-pro-7-15iph11-bios","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/yoga-pro-7-15iph11-bios"}]}