Vulnerability threat dossier

CVE-2026-51990

Vendor unknownProduct mapping pending

An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote attacker to execute arbitrary code via the biz_helper.exe component

VTP deterministic threat16.7of 100 · CVSS excluded

VTP analyst assessment

Sogou Input Method remote code execution

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateCANDIDATE CREATED
AI priorityHIGH
AI confidence60%
Public exploitation · VTP factREPORTED

Assessment

BleepingComputer reported that a China-aligned espionage group exploited CVE-2026-51990 to deploy the GrayRabbit backdoor. The flaw in Sogou Input Method before 16.3.0.3498 allows remote arbitrary code execution through biz_helper.exe.

Why it matters

  • Input-method software runs on Windows endpoints where code execution can establish an initial foothold.
  • Version 16.3.0.3498 fixes the issue.

Evidence

2 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

The campaign report is press reporting with unknown source independence.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

If you use Sogou Input Method for Windows, update to 16.3.0.3498 or later and investigate GrayRabbit-related activity using the reporting source's published guidance.

AI baseline history (5)
  1. BASELINE ASSESSED
    Sogou Input Method remote code executiongpt-5.6-terra · low
  2. BASELINE ASSESSED
    Reported GrayRabbit deployment through Sogou Input Methodgpt-5.6-terra · low
  3. BASELINE ASSESSED
    Reported exploitation of Tencent Sogou Input Method flawgpt-5.6-terra · low
  4. BASELINE ASSESSED
    Reported exploitation of a Sogou Input Method flawgpt-5.6-terra · low
  5. BASELINE ASSESSED
    Insufficient CVE-specific evidencegpt-5.6-terra · low
Technical severityCRITICALCVSS 9.8 · technical context
Public exploitationREPORTEDGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS0.0161th percentile · prediction
Evidence confidence60%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    EPSS is 0.01; this is predictive context, not exploitation evidence.

  2. 02

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

No material changes are recorded for this subject.

03

Claim provenance

Evidence and source independence

4publications detected
4underlying evidence chains

0 primary sources · 0 dependent secondary reports · 4 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
60%claim confidence
UNKNOWNreport:c243a25f3875106b22c5a0aec44c51d16db30206b0a46643b5112657d597930dACTIVE
Evidence
04

Event history

Threat timeline

  1. 14:2613 Sept
    EXPLOITATION REPORTED

    Exploitation Reported

    BleepingComputer supplied a deterministically extracted signal; review the linked evidence before escalation.

05

Original publications

Source record

⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits

AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also crossing lines on their own. That is not a great combination. The rest of the week is more familiar: old bugs still working, fresh exploit chains, exposed systems, weak defaults, and simple paths that should have been harder to abuse. A few of

CVE-2021-24084CVE-2021-38003CVE-2021-41379CVE-2025-20701CVE-2025-53521CVE-2026-10090CVE-2026-12645CVE-2026-12646CVE-2026-12647CVE-2026-12650CVE-2026-12744CVE-2026-12745CVE-2026-18667CVE-2026-20293CVE-2026-26084CVE-2026-33197CVE-2026-42016CVE-2026-42018CVE-2026-44756CVE-2026-50656CVE-2026-51990CVE-2026-58240CVE-2026-61578CVE-2026-61582CVE-2026-61583CVE-2026-61584CVE-2026-61585CVE-2026-61587CVE-2026-61600CVE-2026-61601CVE-2026-61602CVE-2026-6485CVE-2026-67401CVE-2026-69414CVE-2026-70647CVE-2026-70648CVE-2026-76578CVE-2026-78546CVE-2026-78547CVE-2026-81578CVE-2026-81963CVE-2026-82078CVE-2026-82329CVE-2026-82533CVE-2026-84282CVE-2026-84286CVE-2026-84388CVE-2026-84390CVE-2026-84393CVE-2026-85046CVE-2026-85102CVE-2026-85103CVE-2026-85706CVE-2026-85880CVE-2026-87491
Separate evidence group
Original

Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution

The Chinese-language input method editor for Windows can allow attackers to execute arbitrary code remotely. The post Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution appeared first on SecurityWeek .

CVE-2026-51990
Separate evidence group
Original

Hackers exploit Tencent app flaw to deploy GrayRabbit malware

Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor. [...]

CVE-2026-51990
Separate evidence group
Original

China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor

A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security company Gen Digital said in&nbsp;research published Thursday. The attack started with a crafted link and ended with the attacker able to do anything the logged-in user could do. Tencent, which owns

CVE-2021-38003CVE-2026-51990
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score16.7vtp-threat-v1-public
Public exploitation12 / 30
EPSS prediction0.2 / 20
Exploit availability2.5 / 15
Source independence0 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-94
CPE records
0
Deterministic history records
10
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.