CVE-2026-20987: Samsung Mobile Galaxydiagnostics

High severity, CVSS 8.7. EPSS: 0.2% chance of exploitation in the next 30 days.

Improper input validation in GalaxyDiagnostics prior to version 3.5.050 allows local privileged attackers to execute privileged commands.

Affected products

Published 2026-02-04. Last modified 2026-06-17.