CVE-2026-1068: Lenovo Filez

Medium severity, CVSS 5.3. EPSS: 0.1% chance of exploitation in the next 30 days.

An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to obtain sensitive user data from the application.

Affected products

  • Lenovo Filez: before 10.12.3.0 (fixed in 10.12.3.0); before 11.1.0.35 (fixed in 11.1.0.35)

Published 2026-03-11. Last modified 2026-08-19.