CVE-2026-21366 – Qualcomm Snapdragon
“A critical wireless memory flaw leads a broader set of Snapdragon weaknesses that can threaten device security and availability.”
Qualcomm Snapdragon updates address eight vulnerabilities across wireless, authentication, fingerprint, device-driver, fastboot, and security-capability processing. CVE-2026-25289 has a CVSS score of 9.6, Critical severity, and involves memory corruption while processing malformed NAN Service Discovery frames. CVE-2026-24079 has a CVSS score of 8.1, High severity. CVE-2026-21366, CVE-2026-24080, and CVE-2026-24083 each have a CVSS score of 7.8, High severity. CVE-2026-25292, CVE-2026-24084, and CVE-2026-25288 have CVSS scores of 7.6, 7.5, and 7.4 respectively, all High severity.
The vulnerabilities include memory corruption, authentication weaknesses, and denial-of-service conditions. Several flaws present code execution or privilege escalation risk, making the Critical wireless vulnerability and High-severity memory-safety issues the primary concerns.
CVE List:
CVE-2026-25289 (9.6)
CVE-2026-24079 (8.1)
CVE-2026-21366 (7.8)
CVE-2026-24080 (7.8)
CVE-2026-24083 (7.8)
CVE-2026-24084 (7.5)
CVE-2026-25288 (7.4)
CVE-2026-25292 (7.6)
Key Details
- Affected Product
- Qualcomm Lemans Au Lgit Firmware
- Attack Vector
- Local
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- None
- CWE Classification
- CWE-190