CVE-2026-25254: Qualcomm Software Center

Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper authorization leads to Remote Code Execution via SocketIO interface.

Affected products

  • Qualcomm Software Center: version 1.17.1 only; version 1.19.1 only; version 1.21.0 only

Published 2026-09-22. Last modified 2026-09-25.