CVE-2026-42936: Sbi Securities Co.,ltd Hyper Sbi 2
High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.
The installer of HYPER SBI 2 insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privilege of the user invoking the installer.
Affected products
- Sbi Securities Co.,ltd Hyper Sbi 2: before 3.20.0 (fixed in 3.20.0)
Published 2026-07-15. Last modified 2026-07-15.