CVE-2026-51990

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-51990 is a remote code execution (RCE) vulnerability identified in Sogou Input Method for Windows, a widely used typing software in China. This flaw enables remote attackers to install malicious programs on a user's system through a single click. The exploit chain leverages an unvalidated protocol parameter, an outdated Chromium browser engine that operates without a sandbox, and disabled web security controls within the application. Security researchers discovered that threat actors, specifically the UNC3569 group, actively exploited this vulnerability in the wild to deploy the GRAYRABBIT backdoor. The attack typically begins when a user clicks a specially crafted web link, which then triggers the vulnerability within Sogou Input Method to execute malicious code. Tencent, the developer of Sogou Input Method, addressed this issue by releasing an automatic software patch in April 2026.

Description
-

Social media

Hype score
Not currently trending
  1. ⚠️🐰 Tencent flaw deploys GrayRabbit CVE-2026-51990 enables RCE through Sogou Input Method; fixed in version 16.3. 🔗 read more: https://t.co/5E6aQuKLgu #ransomNews #cyberthreats #GrayRabbit

    @ransomnews

    14 Sept 2026

    132 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. ⚠️ Tencent Sogou Input Method : CVE-2026-51990 est activement exploitée par le groupe lié à la Chine UNC3569 pour déployer la backdoor GRAYRABBIT. Correctif disponible depuis la version 16.3.0.3498 : mettez à jour immédiatement. #Cyber #Tencent

    @TwitGri

    14 Sept 2026

    149 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Hackers are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method to deploy GrayRabbit malware. Prioritize patching and monitoring for infections. Stay updated with SOC Minute. #GrayRabbit #Tencent #SOCMinute https://t.co/OBP8IfynPc

    @SOCMinute

    14 Sept 2026

    33 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Tencent Patches Critical Sogou Input Method RCE Flaw Exploited by UNC3569 Threat actors are actively exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method to… Full write-up → link in bio #cybersecurity #infosec #VulnerabilityDisclosure #tencen

    @HotaSamit

    14 Sept 2026

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🔒 Hackers exploit Tencent app flaw to deploy GrayRabbit malware Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in ... #CyberSecurity #InfoSec #CrustyTLDR

    @crustyclaws

    13 Sept 2026

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🇨🇳🚨 CHINA-LINKED HACKERS EXPLOITED CRITICAL SOGOU INPUT METHOD FLAW TO DEPLOY GRAYRABBIT BACKDOOR Gen Threat Labs has disclosed active exploitation of CVE-2026-51990, a critical vulnerability affecting Tencent's Sogou Input Method for Windows. The vulnerability was dis

    @DailyDarkWeb

    13 Sept 2026

    1759 Impressions

    0 Retweets

    2 Likes

    2 Bookmarks

    1 Reply

    0 Quotes

  7. 🚨 Tencent’in Sogou Input Method’u hedefte! CVE-2026-51990 kritik açığını sömüren saldırganlar, Windows sistemlerine GrayRabbit backdoor’u yerleştiriyor. Açığın Çin bağlantılı bir casusluk grubuyla ilişkili saldırılarda kullanıldığı belirtiliyor.

    @KubbeSiber

    13 Sept 2026

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. CVE-2026-51990 in Tencent's Sogou Input Method for Windows is being exploited by China-aligned actors to deploy the GrayRabbit backdoor.

    @thecircuitry_

    13 Sept 2026

    51 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  9. إن كنت تستخدم تطبيق Sogou Input Method على ويندوز، أوقفه الآن. رصدت استغلالاً فعلياً لثغرة حرجة (CVE-2026-51990) لنشر برمجية GrayRabbit الخبيثة من قبل جهة تهديد مدعومة من دولة

    @RapidSSar

    13 Sept 2026

    4 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  10. CVE-2026-51990 in Tencent's Sogou Input Method is actively exploited by UNC3569 to deploy GrayRabbit via a crafted sgbiz: URI triggering biz_helper.exe. The 64-bit backdoor uses RC4-encoded C2 and reflective plugin loading. #DFIR_Radar https://t.co/FAY5Y06BBp

    @DFIR_Radar

    13 Sept 2026

    206 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  11. MiniMagi CTI report by Raita Ode 2026-09-14−00:00 JST 【分野】マルウェア・標的型攻撃キャンペーン・対策 【生成AIによる分析・投稿】 **攻撃の特徴と検知ポイント** 中国系諜報グループ(UNC3569)が、Tencent 製「搜狗输

    @RaitaOde

    13 Sept 2026

    206 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.