LIVE · cybersecurity feed
Live wire
vendor

Samsung

38 CVEs published in the last four months and 1 stories. Exploited flaws first.

Critical2
High23
Medium11
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-209989.8criticalsmart switchImproper authentication in Smart Switch prior to version 3.7.69.15 allows remote attackers to bypass authenticatio173d ago
CVE-2026-209979.8criticalsmart switchImproper verification of cryptographic signature in Smart Switch prior to version 3.7.69.15 allows remote attacker173d ago
CVE-2026-89158.8highescargotOut-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers.101d ago
CVE-2026-209908.1highandroidImproper export of android application components in Secure Folder prior to SMR Mar-2026 Release 1 allows local at173d ago
CVE-2026-210727.8highandroidImproper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to w26d ago
CVE-2026-473147.8highescargotOut-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers.109d ago
CVE-2026-210207.8highandroidImproper export of android application components in OmaCP prior to SMR May-2026 Release 1 allows local attackers 115d ago
CVE-2026-473107.8highescargotUse after free vulnerability in Samsung Open Source Escargot allows Pointer Manipulation.109d ago
CVE-2026-473117.8highescargotHeap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers.109d ago
CVE-2026-210297.8highandroidImproper export of android application components in Galaxy Editing Service prior to SMR Jun-2026 Release 1 allows92d ago
CVE-2026-210307.8highandroidImproper access control in MediaTek Audio HAL prior to SMR Jun-2026 Release 1 allows local attackers to trigger pr92d ago
CVE-2026-210317.8highandroidImproper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activ92d ago
CVE-2026-210657.8highandroidOut-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out26d ago
CVE-2026-210667.8highandroidImproper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to wr26d ago
CVE-2026-210677.8highandroidImproper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bou26d ago
CVE-2026-210687.8highandroidStack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to 26d ago
CVE-2026-210697.8highandroidIncorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows loc26d ago
CVE-2026-210717.8highandroidImproper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to26d ago
CVE-2026-209997.5highsmart switchAuthentication bypass by replay in Smart Switch prior to version 3.7.69.15 allows remote attackers to trigger priv173d ago
CVE-2026-210357.5highplus tvImproper input validation in Samsung Plus TV prior to version 1.0.28.6 allows remote attackers to access sensitive92d ago
CVE-2026-210377.1highmembersImproper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary 92d ago
CVE-2026-210587.1highandroidImproper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete fil26d ago
CVE-2026-210597.1highandroidImproper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local26d ago
CVE-2026-210327.1highassistantImproper export of android application components in SmartHomeWidgetReceiver of Samsung Assistant prior to version92d ago
CVE-2026-210337.1highassistantImproper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to versi92d ago
CVE-2026-210046.5mediumsmart switchImproper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial o173d ago
CVE-2026-210056.5mediumsmart switchPath traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arbitrary files w173d ago
CVE-2026-209946.1mediumaccountURL redirection in Samsung Account prior to version 15.5.01.1 allows local attackers to potentially get access tok173d ago
CVE-2026-209935.5mediumassistantImproper export of android application components in Samsung Assistant prior to version 9.3.10.7 allows local atta173d ago
CVE-2026-210025.5mediumgalaxy storeImproper verification of cryptographic signature in Galaxy Store prior to version 4.6.03.8 allows local attacker t173d ago
CVE-2026-210005.5mediumgalaxy storeImproper access control in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy173d ago
CVE-2026-210015.5mediumgalaxy storePath traversal in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store pr173d ago
CVE-2026-209955.3mediumsmart switchExposure of sensitive functionality to an unauthorized actor in Smart Switch prior to version 3.7.69.15 allows rem173d ago
CVE-2026-209965.3mediumsmart switchUse of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.69.15 allows remote attacker173d ago
CVE-2026-209885mediumandroidImproper verification of intent by broadcast receiver in Settings prior to SMR Mar-2026 Release 1 allows local att173d ago
CVE-2026-209914.4mediumandroidImproper privilege management in ThemeManager prior to SMR Mar-2026 Release 1 allows local privileged attackers to173d ago
CVE-2026-209923.3lowandroidImproper authorization in Settings prior to SMR Mar-2026 Release 1 allows local attacker to disable configuring th173d ago
CVE-2026-209892.4lowandroidImproper verification of cryptographic signature in Font Settings prior to SMR Mar-2026 Release 1 allows physical 173d ago

Filter the full tracker by Samsung

Our coverage of Samsung

e-commerce fraudhigh

Fake shops target shoppers across Europe with fake Samsung deals, counterfeit goods and World Cup scams

Cybercriminals are orchestrating sophisticated, multinational fake online shop operations across Europe, impersonating major brands like Samsung, Nike, and Amazon. These scams leverage social media, WhatsApp, and email to trick consumers into purchasing counterfeit goods, sharing personal information, or falling victim to World Cup-themed promotions. The operations are highly organized, utilizing rotating domains, misleading redirects, and localized content to evade detection and maximize reach.