CVE-2026-81579: Wibu-Systems-AG Wibukey
High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.
In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64-bit Windows allows an attacker to exploit a write-what-where primitive, enabling local privilege escalation. This can be leveraged to execute arbitrary code, run an administrator shell, or gain full control over the system.
Affected products
- Wibu-Systems-AG Wibukey: before 6.71 (fixed in 6.71)
Published 2026-08-27. Last modified 2026-09-03.