Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · acer

acer

· 1 Critical

Total CVEs

21

Critical

1

Products

110

Search All CVEs →

21

Products (110)

ac700 chromebook8 CVEslunchapp.aplunch2 CVEscare center2 CVEsaltos t110 f3 firmware1 CVEsaltos w2000h-w570h f41 CVEsaltos w2000h-w570h f4 firmware1 CVEsap130 f21 CVEsap130 f2 firmware1 CVEsaspire 1600x1 CVEsaspire 1600x firmware1 CVEsaspire 1602m1 CVEsaspire 1602m firmware1 CVEsaspire 7600u1 CVEsaspire 7600u firmware1 CVEsaspire a115-211 CVEsaspire a115-21 firmware1 CVEsaspire a315-221 CVEsaspire a315-22 firmware1 CVEsaspire a315-22g1 CVEsaspire a315-22g firmware1 CVEsaspire e5-475g1 CVEsaspire e5-475g firmware1 CVEsaspire mc6051 CVEsaspire mc605 firmware1 CVEsaspire tc-1051 CVEsaspire tc-105 firmware1 CVEsaspire tc-1201 CVEsaspire tc-120 firmware1 CVEsaspire u5-6201 CVEsaspire u5-620 firmware1 CVEsaspire x19351 CVEsaspire x1935 firmware1 CVEsaspire x34751 CVEsaspire x3475 firmware1 CVEsaspire x39951 CVEsaspire x3995 firmware1 CVEsaspire xc1001 CVEsaspire xc100 firmware1 CVEsaspire xc6001 CVEsaspire xc600 firmware1 CVEsaspire z3-6151 CVEsaspire z3-615 firmware1 CVEsc720 chromebook1 CVEschromebase1 CVEschromebase 241 CVEschromebook 11 c7301 CVEschromebook 11 c730e1 CVEschromebook 11 c7351 CVEschromebook 11 c7401 CVEschromebook 11 c7711 CVEschromebook 11 c771t1 CVEschromebook 11 n7 c7311 CVEschromebook 13 cb5-3111 CVEschromebook 14 cb3-4311 CVEschromebook 14 for work cp5-4711 CVEschromebook 15 cb3-5311 CVEschromebook 15 cb3-5321 CVEschromebook 15 cb5-5711 CVEschromebook r111 CVEschromebook r13 cb5-312t1 CVEschromebox1 CVEschromebox cxi21 CVEsextensa ex215-211 CVEsextensa ex215-21 firmware1 CVEsextensa ex215-21g1 CVEsextensa ex215-21g firmware1 CVEsquick access1 CVEsquickaccess1 CVEssk-96621 CVEssk-9662 firmware1 CVEsveriton b630 491 CVEsveriton b630 49 firmware1 CVEsveriton e4301 CVEsveriton e430 firmware1 CVEsveriton e430g1 CVEsveriton e430g firmware1 CVEsveriton m2110g1 CVEsveriton m2110g firmware1 CVEsveriton m2120g1 CVEsveriton m2120g firmware1 CVEsveriton m26111 CVEsveriton m2611 firmware1 CVEsveriton m2611g1 CVEsveriton m2611g firmware1 CVEsveriton m46201 CVEsveriton m4620 firmware1 CVEsveriton m4620g1 CVEsveriton m4620g firmware1 CVEsveriton m6620g1 CVEsveriton m6620g firmware1 CVEsveriton n2620g1 CVEsveriton n2620g firmware1 CVEsveriton n4620g1 CVEsveriton n4620g firmware1 CVEsveriton n4630g1 CVEsveriton n4630g firmware1 CVEsveriton s6620g1 CVEsveriton s6620g firmware1 CVEsveriton x26111 CVEsveriton x2611 firmware1 CVEsveriton x2611g1 CVEsveriton x2611g firmware1 CVEsveriton x4620g1 CVEsveriton x4620g firmware1 CVEsveriton x6620g1 CVEsveriton x6620g firmware1 CVEsveriton z2650g1 CVEsveriton z2650g firmware1 CVEsacer portal1 CVEsaltos t110 f31 CVEs

Recent Vulnerabilities

View all 21
CVE-2023-48034MEDIUM 6.1

An issue discovered in Acer Wireless Keyboard SK-9662 allows attacker in physical proximity to both decrypt wireless keystrokes and inject arbitrary keystrokes via use of weak encryption.

CVE-2022-40080HIGH 7.8

Stack overflow vulnerability in Aspire E5-475G 's BIOS firmware, in the FpGui module, a second call to GetVariable services allows local attackers to execute arbitrary code in the UEFI DXE phase and gain escalated privileges.

CVE-2022-4020HIGH 8.1

Vulnerability in the HQSwSmiDxe DXE driver on some consumer Acer Notebook devices may allow an attacker with elevated privileges to modify UEFI Secure Boot settings by modifying an NVRAM variable.

CVE-2022-41415CRITICAL 9.8

Acer Altos W2000h-W570h F4 R01.03.0018 was discovered to contain a stack overflow in the RevserveMem component. This vulnerability allows attackers to cause a Denial of Service (DoS) via injecting crafted shellcode into the NVRAM variable.

CVE-2022-30426HIGH 7.8

There is a stack buffer overflow vulnerability, which could lead to arbitrary code execution in UEFI DXE driver on some Acer products. An attack could exploit this vulnerability to escalate privilege from ring 3 to ring 0, and hijack control flow during UEFI DXE execution. This affects Altos T110 F3 firmware version <= P13 (latest) and AP130 F2 firmware version <= P04 (latest) and Aspire 1600X firmware version <= P11.A3L (latest) and Aspire 1602M firmware version <= P11.A3L (latest) and Aspire 7600U firmware version <= P11.A4 (latest) and Aspire MC605 firmware version <= P11.A4L (latest) and Aspire TC-105 firmware version <= P12.B0L (latest) and Aspire TC-120 firmware version <= P11-A4 (latest) and Aspire U5-620 firmware version <= P11.A1 (latest) and Aspire X1935 firmware version <= P11.A3L (latest) and Aspire X3475 firmware version <= P11.A3L (latest) and Aspire X3995 firmware version <= P11.A3L (latest) and Aspire XC100 firmware version <= P11.B3 (latest) and Aspire XC600 firmware version <= P11.A4 (latest) and Aspire Z3-615 firmware version <= P11.A2L (latest) and Veriton E430G firmware version <= P21.A1 (latest) and Veriton B630_49 firmware version <= AAP02SR (latest) and Veriton E430 firmware version <= P11.A4 (latest) and Veriton M2110G firmware version <= P21.A3 (latest) and Veriton M2120G fir.

CVE-2022-24286HIGH 7.8

Acer QuickAccess 2.01.300x before 2.01.3030 and 3.00.30xx before 3.00.3038 contains a local privilege escalation vulnerability. The user process communicates with a service of system authority through a named pipe. In this case, the Named Pipe is also given Read and Write rights to the general user. In addition, the service program does not verify the user when communicating. A thread may exist with a specific command. When the path of the program to be executed is sent, there is a local privilege escalation in which the service program executes the path with system privileges.

CVE-2022-24285HIGH 7.8

Acer Care Center 4.00.30xx before 4.00.3042 contains a local privilege escalation vulnerability. The user process communicates with a service of system authority called ACCsvc through a named pipe. In this case, the Named Pipe is also given Read and Write rights to the general user. In addition, the service program does not verify the user when communicating. A thread may exist with a specific command. When the path of the program to be executed is sent, there is a local privilege escalation in which the service program executes the path with system privileges.

CVE-2021-45975HIGH 7.8

In ListCheck.exe in Acer Care Center 4.x before 4.00.3038, a vulnerability in the loading mechanism of Windows DLLs could allow a local attacker to perform a DLL hijacking attack. This vulnerability is due to incorrect handling of directory search paths at run time. An attacker could exploit this vulnerability by placing a malicious DLL file on the targeted system. This file will execute when the vulnerable application launches. A successful exploit could allow the attacker to execute arbitrary code on the targeted system with local administrator privileges.

CVE-2019-18670HIGH 7.8

In the Quick Access Service (QAAdminAgent.exe) in Acer Quick Access V2.01.3000 through 2.01.3027 and V3.00.3000 through V3.00.3008, a REGULAR user can load an arbitrary unsigned DLL into the signed service's process, which is running as NT AUTHORITY\SYSTEM. This is a DLL Hijacking vulnerability (including search order hijacking, which searches for the missing DLL in the PATH environment variable), which is caused by an uncontrolled search path element for nvapi.dll, atiadlxx.dll, or atiadlxy.dll.

CVE-2017-15361

The Infineon RSA library 1.02.013 in Infineon Trusted Platform Module (TPM) firmware, such as versions before 0000000000000422 - 4.34, before 000000000000062b - 6.43, and before 0000000000008521 - 133.33, mishandles RSA key generation, which makes it easier for attackers to defeat various cryptographic protection mechanisms via targeted attacks, aka ROCA. Examples of affected technologies include BitLocker with TPM 1.2, YubiKey 4 (before 4.3.5) PGP key generation, and the Cached User Data encryption feature in Chrome OS.

CVE-2016-5648

Acer Portal app before 3.9.4.2000 for Android does not properly validate SSL certificates, which allows remote attackers to perform a Man-in-the-middle attack via a crafted SSL certificate.

CVE-2012-2864

Mesa, as used in Google Chrome before 21.0.1183.0 on the Acer AC700, Cr-48, and Samsung Series 5 and 5 550 Chromebook platforms, and the Samsung Chromebox Series 3, allows remote attackers to execute arbitrary code via unspecified vectors that trigger an "array overflow."

CVE-2012-3290

Multiple unspecified vulnerabilities in Google Chrome before 20.0.1132.22 on the Acer AC700; Samsung Series 5, 5 550, and Chromebox 3; and Cr-48 Chromebook platforms have unknown impact and attack vectors.

CVE-2012-1418

Multiple unspecified vulnerabilities in Google Chrome before 17.0.963.60 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.

CVE-2012-0695

Multiple unspecified vulnerabilities in Google Chrome before 17.0.963.27 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.

CVE-2011-4719

Multiple unspecified vulnerabilities in Google Chrome before 16.0.912.63 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.

CVE-2011-4548

Multiple unspecified vulnerabilities in Google Chrome before 16.0.912.44 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.

CVE-2011-3421

Multiple unspecified vulnerabilities in Google Chrome before 14.0.835.125 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.

CVE-2011-3420

Multiple unspecified vulnerabilities in Google Chrome before 14.0.835.157 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.

CVE-2009-2627

Insecure method vulnerability in the Acer LunchApp (aka AcerCtrls.APlunch) ActiveX control in acerctrl.ocx allows remote attackers to execute arbitrary commands via the Run method, a different vulnerability than CVE-2006-6121.

CVE-2006-6121

Acer Notebook LunchApp.APlunch ActiveX control allows remote attackers to execute arbitrary commands by calling the Run method.