CVE-2026-3821: Smci x14dbg-dap,x14dbi

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Supermicro (SMC) SMASH services contain an Arbitrary code execution issue in X14DBG-DAP and X14DBI. An authorized attacker can exploit SMASH’s input capability to compromise data integrity or launch a Denial-of-Service (DoS) attack against the BMC.

Affected products

  • Smci x14dbg-dap,x14dbi: version 01.00.16.00 only; version 1.03.02.06 only

Published 2026-07-22. Last modified 2026-07-23.