PatchSiren

Bitdefender CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Bitdefender CVE published 2026-07-14

CVE-2026-6851

CVE-2026-6851 is an Improper link resolution before file access ('link following') vulnerability in the File Shredder module used in Bitdefender Total Security and Internet Security on Windows. The issue allows a less-privileged local user to elevate rights by leveraging a race condition via Symbolic Links. This issue affects Total Security: before 27.0.58.315; Internet Security: before 27.0.58.315. The v [truncated]

HIGH Bitdefender CVE published 2025-12-10

CVE-2025-7073

A local privilege escalation vulnerability in Bitdefender Total Security and related products allows low-privileged attackers to elevate privileges through a multi-stage attack chain. The vulnerability stems from improper symbolic link validation in the bdservicehost.exe service, which deletes files from a user-writable directory (C:ProgramDataAtcFeedback) without adequate security checks. This arbitrary [truncated]