Users of Tencent's Sogou Input Method for Windows should update the application to the latest available version immediately. It is recommended to monitor official Tencent security advisories for patch releases and further technical details. Administrators should enforce update policies and consider temporary deployment restrictions if immediate updating is not feasible. Users should remain vigilant for unusual system behavior and apply network segmentation where possible to limit potential impact.
Quick answers
What is CVE-2026-51990?
Users of Tencent's Sogou Input Method for Windows should update the application to the latest available version immediately. It is recommended to monitor official Tencent security advisories for patch releases and further technical details. Administrators should enforce update policies and consider temporary deployment restrictions if immediate updating is not feasible. Users should remain vigilant for unusual system behavior and apply network segmentation where possible to limit potential impact.
How severe is CVE-2026-51990?
high
Is CVE-2026-51990 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-51990 be mitigated?
Users of Tencent's Sogou Input Method for Windows should update the application to the latest available version immediately. It is recommended to monitor official Tencent security advisories for patch releases and further technical details. Administrators should enforce update policies and consider temporary deployment restrictions if immediate updating is not feasible. Users should remain vigilant for unusual system behavior and apply network segmentation where possible to limit potential impact.
CVSS
—
Vendor
Tencent
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
Sogou Input Method for Windows
Mitigation
Users of Tencent's Sogou Input Method for Windows should update the application to the latest available version immediately. It is recommended to monitor official Tencent security advisories for patch releases and further technical details. Administrators should enforce update policies and consider temporary deployment restrictions if immediate updating is not feasible. Users should remain vigilant for unusual system behavior and apply network segmentation where possible to limit potential impact.
Threat actors are exploiting a critical vulnerability in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor. The vulnerability, reported as CVE-2026-51990, is being exploited by actors linked to a China-aligned espionage group. Successful exploitation may result in unauthorized access and control of affected systems. As of the report, specific patch details and the full exploitation vector have not been disclosed. Users are advised to update Sogou Input Method to the latest version and monitor official Tencent security advisories.