SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-9805

LOW · CVSS 2.7 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The vulnerability exists in the SMM IHISI command handler's FMTSWriteUseIntelLib function, which processes FMTS command 0x32 without proper buffer size validation, potentially leading to a buffer overflow. While the severity is rated low, this flaw could be exploited to execute arbitrary code or crash the system. Organizations using affected products should prioritize patching this vulnerability to mitigate potential risks associated with buffer overflow attacks.

CVE
CVE-2026-9805
Severity
LOW
CVSS
2.7
EPSS
0.12%

Original NVD Description

SMM IHISI command handler, FMTSWriteUseIntelLib, for FMTS command 0x32, read and write data without checking buffer size and could cause buffer overflow.