CVE-2026-12166: Little Orbit Gamefirst Anti-Cheat

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

A NULL pointer dereference vulnerability for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to cause a denial of service via crafted requests that trigger a system crash.

Affected products

  • Little Orbit Gamefirst Anti-Cheat: up to and including 2025-07-07

Published 2026-07-02. Last modified 2026-07-02.