PatchSiren cyber security CVE debrief
CVE-2026-25264 Qualcomm, Inc. CVE debrief
CVE-2026-25264 is a high-severity vulnerability in Qualcomm's Software Center, allowing for privilege escalation due to weak configuration during package extraction. The CVE record was published on 2026-09-22T10:17:09.110Z and last modified on 2026-09-25T13:37:47.870Z. The NVD entry is currently Analyzed. This vulnerability affects Qualcomm Software Center installations and has a CVSS score of 8.8. Defenders and administrators responsible for Qualcomm Software Center installations should assess exposure and prioritize remediation, especially in environments where local privilege escalation could have significant impacts. The vulnerability is classified as CWE-427. The CVE Program,
- Vendor
- Qualcomm, Inc.
- Product
- Snapdragon
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-22
- Original CVE updated
- 2026-09-25
- Advisory published
- 2026-09-22
- Advisory updated
- 2026-09-25
Who should care
Defenders and administrators responsible for Qualcomm Software Center installations, especially in environments where local privilege escalation could have significant impacts, should assess exposure and prioritize remediation.
Why it matters
CVE-2026-25264 is a high-severity vulnerability in Qualcomm's Software Center that allows for privilege escalation. Defenders should prioritize verifying and remediating affected installations, especially in environments where local privilege escalation could have significant impacts.
- Local privilege escalation could allow attackers to gain elevated access
- Weak configuration during package extraction increases risk of exploitation
- Remediation requires patching or updating affected Qualcomm Software Center versions
Technical summary
CVE-2026-25264 is a high-severity vulnerability in Qualcomm's Software Center, allowing for privilege escalation due to weak configuration during package extraction. The vulnerability has a CVSS score of 8.8 and is classified as CWE-427. This vulnerability affects Qualcomm Software Center installations, particularly versions 1.17.1, 1.19.1, 1.21.0, 1.22.1, 1.25.1, and 1.26.0. Defenders should prioritize verifying and remediating affected Qualcomm Software Center installations, especially in environments where local privilege escalation could have significant } }
Defensive priority
Defenders should prioritize verifying and remediating affected Qualcomm Software Center installations, especially in environments where local privilege escalation could have significant impacts.
Recommended defensive actions
- Verify Qualcomm Software Center versions 1.17.1, 1.19.1, 1.21.0, 1.22.1, 1.25.1, and 1.26.0 for vulnerability
- Apply patches or updates provided by Qualcomm to remediate the vulnerability
- Review and strengthen configuration for package extraction processes
Evidence notes
The CVE record and NVD detail page provide official information on the vulnerability. A vendor advisory from Qualcomm is also available, offering guidance on addressing the issue.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-25264 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-25264
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-25264 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-25264
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2026-bulletin.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.