PatchSiren

Wellbia CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Wellbia CVE published 2026-05-11

CVE-2026-3609

The CVE-2026-3609 vulnerability exists in Wellbia's XIGNCODE3 xhunter1.sys kernel driver, versions 10.0.10011.16384 through 2023.12.7.78. This privilege escalation vulnerability allows any user process to request a PROCESS_ALL_ACCESS through the IRP_MJ_WRITE command interface. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. System administrators and security teams responsible [truncated]