PatchSiren cyber security CVE debrief
CVE-2026-25282 Qualcomm, Inc. CVE debrief
A transient denial of service (DOS) vulnerability was discovered in a product from Qualcomm, which could lead to out-of-bound memory access when processing unverified data from a neighboring system. The CVE record was published on 2026-09-17T05:17:01.253Z and was last modified on 2026-09-18T19:06:08.407Z. The NVD entry is currently Undergoing Analysis.
- Vendor
- Qualcomm, Inc.
- Product
- Snapdragon
- CVSS
- HIGH 7.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-17
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-09-17
- Advisory updated
- 2026-09-18
Who should care
Defenders responsible for systems using Qualcomm products should assess exposure and potential for DOS attacks. Remediation priority is high due to the high CVSS score.
Why it matters
Defenders should prioritize verifying exposure in systems using Qualcomm products and assess the potential for DOS attacks due to the high CVSS score and potential for out-of-bound memory access.
- Potential for denial of service (DOS) attacks
- Need for verification of exposure in systems using Qualcomm products
- Remediation priority due to high CVSS score
- Potential for out-of-bound memory access
Technical summary
The CVE-2026-25282 vulnerability is a transient denial of service (DOS) issue that occurs when processing unverified data from a neighboring system, leading to out-of-bound memory access. The CVSS score is 7.9, indicating a high severity. This issue was discovered in a product from Qualcomm. Defenders should assess exposure in systems using Qualcomm products and prioritize remediation due to the high CVSS score and potential for out-of-bound memory access.
Defensive priority
Defenders should prioritize verifying exposure in systems using Qualcomm products and assess the potential for DOS attacks. Remediation priority is high due to the high CVSS score.
Recommended defensive actions
- Verify exposure in systems using Qualcomm products
- Assess potential for DOS attacks
- Monitor for updates from Qualcomm on remediation
Evidence notes
The CVE record and NVD detail page provide information on the vulnerability, but the scope of affected products and versions is not clearly stated. The Qualcomm security bulletin may provide additional information.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-25282 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-25282
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-25282 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-25282
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://docs.qualcomm.com/product/publicresources/securitybulletin/september-2026-bulletin.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.