tag
Exploit-Chain
Critical
TP-Link Tapo C260 Unauthenticated-to-Root RCE Chain — CVE-2026-0651
CVE-2026-0651 (chained with CVE-2026-0652, CVE-2026-0653)·
TP-Link Tapo C260 IP camera (pre-patch firmware, shared /bin/main omnibus binary across models)
unpatched
Critical
Samsung Android AT-Command Filter Bypass to system_server Code Execution (CVE-2026-20980)
CVE-2026-20980 (chained with CVE-2026-20981 and CVE-2026-20982)·
Samsung Android AT-command distribution stack (at_distributor / libpacm_client.so, FacAtFunction system app, ShortcutService)
unpatched