A vulnerability labeled as critical has been found in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown functionality of the file C:\Program Files (x86)\Razer\RzUpdateEngineService\RzUpdateService.exe of the component Named Pipe Handler. Executing a manipulation of the argument lpThreadParameter can lead to improper privilege management.
This vulnerability appears as CVE-2026-18606. The attack requires local access. In addition, an exploit is available.
The vendor was contacted early about this disclosure.
Intelligence View
⚡ tsecurity.de Intelligence
CVE-2026-18606 | Razer RzUpdateService 1.10.14.0 Named Pipe RzUpdateService.exe lpThreadParameter privileges management (EUVD-2026-52351)
A vulnerability labeled as critical has been found in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown functionality of the file C:\Program Files (x86)\Razer\RzUpdateEngineService\RzUpdateService.exe of the…
Reagiere als Erste:r — dein Feedback zählt!
2. Cyber Threat Intelligence & Forensik
IoC Intelligence (2 Indikatoren)
CVE-2026-186061[.]10[.]14[.]0
CTI Threat Relationship Graph2 Knoten / 1 Relationen
Exploit & Remediation Lifecycle Timeline
CVE-2026-18606Entdeckung & Meldung
Schwachstelle identifiziert & registriert
Sicherheits-Advisory
Offizielle Warnung & CVE-Zuweisung
Exploit / PoC
Bislang kein öffentlicher Exploit
In-the-Wild Ausnutzung
Keine Massenausnutzung gemeldet
Patch & Schutzmaßnahmen
Noch kein offizieller Patch dokumentiert
Exploit Weaponization & Public PoC Radar
ELEVATED · Index 35/100Exploit-DB
Kein EDB-EintragInteraktion
0-ClickAuthentifizierung
Erforderlich3. Compliance, SLA & Vendor Adherence
CISA-SSVC-Triage (vulnrichment)CVE-2026-18606
Exploitation: poc (PoC verfügbar)Automatable: no (Nicht automatisierbar)Technical Impact: total (Vollständig)
Quelle: CISA-ADP vulnrichment · Stand 2026-08-03T16:56:09.682684Z · CISA Coordinator
Advisory Radar
In herstellerseitiger Prüfung
Hersteller-Sicherheitsmeldungen & Patch-Status
Handlungsempfehlung für Administratoren
Hersteller-Advisory noch nicht formal hinterlegt. Regelmäßiges Re-Scanning der CTI-Quellen anberaumt.
Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
-
Web Referencevuldb.com
-
Web Referencevuldb.com
-
Web Referencevuldb.com
-
Web Referencevuldb.com
-
Web Referenceopcodic.notion.site