PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-25264 Qualcomm, Inc. CVE debrief

CVE-2026-25264 is a high-severity vulnerability in Qualcomm's Software Center, allowing for privilege escalation due to weak configuration during package extraction. The CVE record was published on 2026-09-22T10:17:09.110Z and last modified on 2026-09-25T13:37:47.870Z. The NVD entry is currently Analyzed. This vulnerability affects Qualcomm Software Center installations and has a CVSS score of 8.8. Defenders and administrators responsible for Qualcomm Software Center installations should assess exposure and prioritize remediation, especially in environments where local privilege escalation could have significant impacts. The vulnerability is classified as CWE-427. The CVE Program,

Vendor
Qualcomm, Inc.
Product
Snapdragon
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-22
Original CVE updated
2026-09-25
Advisory published
2026-09-22
Advisory updated
2026-09-25

Who should care

Defenders and administrators responsible for Qualcomm Software Center installations, especially in environments where local privilege escalation could have significant impacts, should assess exposure and prioritize remediation.

Why it matters

CVE-2026-25264 is a high-severity vulnerability in Qualcomm's Software Center that allows for privilege escalation. Defenders should prioritize verifying and remediating affected installations, especially in environments where local privilege escalation could have significant impacts.

  • Local privilege escalation could allow attackers to gain elevated access
  • Weak configuration during package extraction increases risk of exploitation
  • Remediation requires patching or updating affected Qualcomm Software Center versions

Technical summary

CVE-2026-25264 is a high-severity vulnerability in Qualcomm's Software Center, allowing for privilege escalation due to weak configuration during package extraction. The vulnerability has a CVSS score of 8.8 and is classified as CWE-427. This vulnerability affects Qualcomm Software Center installations, particularly versions 1.17.1, 1.19.1, 1.21.0, 1.22.1, 1.25.1, and 1.26.0. Defenders should prioritize verifying and remediating affected Qualcomm Software Center installations, especially in environments where local privilege escalation could have significant } }

Defensive priority

Defenders should prioritize verifying and remediating affected Qualcomm Software Center installations, especially in environments where local privilege escalation could have significant impacts.

Recommended defensive actions

  • Verify Qualcomm Software Center versions 1.17.1, 1.19.1, 1.21.0, 1.22.1, 1.25.1, and 1.26.0 for vulnerability
  • Apply patches or updates provided by Qualcomm to remediate the vulnerability
  • Review and strengthen configuration for package extraction processes

Evidence notes

The CVE record and NVD detail page provide official information on the vulnerability. A vendor advisory from Qualcomm is also available, offering guidance on addressing the issue.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-25264 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-25264

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-25264 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-25264

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2026-bulletin.html

    [email protected] - Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.