CVE-2026-51990 carries a CVSS 3.1 base score of 9.8 against Sogou Input Method, a Chinese-language input method editor. NVD classifies it as CWE-94 (Improper Control of Generation of Code) and states the issue is fixed in version 16.3.0.3498, meaning releases before that version are affected. VulnCheck’s KEV feed reports the CVE as exploited, dated September 10, 2026.
That exploitation report is single-sourced. CISA has not added CVE-2026-51990 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion on September 19, 2026. VulnCheck’s catalog admits vendor and researcher exploitation reporting on broader criteria than CISA’s own listing process has accepted; no Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.
What the flaw is
Both NVD and CVE.org carry an identical, terse description: the vulnerability allows a remote attacker to execute arbitrary code via the biz_helper.exe component. That description is corroborated by two independent sources in our source data — a higher bar than most fields in this record clear — but neither source elaborates on the attack vector, delivery mechanism, or what makes biz_helper.exe reachable to a remote party. This is a case where the weakness class and outcome are well-established while the technical mechanism is not documented in our ingested data.
One reference our source data carries, cited by both NVD and CVE.org, is a Gen Digital (Norton/Avast’s parent company) research blog titled around a “one-click backdoor” characterization of this flaw. We link it below as the vendor-cited source it is; that framing and any further technical detail about delivery or exploitation come from Gen Digital’s own research, not from Quietlytic’s independent analysis, and we have not independently verified claims beyond what NVD and CVE.org state in their own description text.
A vendor-attribution conflict worth stating plainly
Our two disclosure-record sources (NVD, CVE.org) both list the vendor as "n/a" — meaning neither one populates a vendor field for this CVE. VulnCheck’s KEV entry, by contrast, attributes the product to Tencent. Sogou Input Method’s developer, Sogou Inc., became a Tencent subsidiary following Tencent’s 2021 acquisition, so VulnCheck’s attribution is plausible on that basis — but it is not corroborated by either of our disclosure-record sources, and we report it as VulnCheck’s characterization rather than an independently confirmed vendor identity. This is exactly the kind of source disagreement the evidence model calls for surfacing rather than silently resolving: two sources say “unspecified,” a third says “Tencent,” and neither position is dismissed here.
Evidence and confidence
- High confidence — the core description (remote code execution via
biz_helper.exe), corroborated independently by NVD and CVE.org. - Medium confidence — the CVSS 9.8 score, the vector (
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), the CWE-94 classification, and the 16.3.0.3498 fixed version, which trace to NVD alone. The exploitation report traces to VulnCheck KEV alone. - Low confidence / conflicting — vendor attribution. NVD and CVE.org record no vendor; VulnCheck records Tencent.
- Unknown — the specific technical mechanism connecting a remote attacker to
biz_helper.exeexecution; neither disclosure record documents it, and we have not treated third-party research beyond the NVD/CVE.org-cited Gen Digital reference as a source of fact for this article.
FIRST’s EPSS model scores this CVE 0.00998, 61.2nd percentile as of our ingestion — moderately above the midpoint of the broader EPSS population.
Why this matters
Input method editors run with deep integration into the operating system by necessity — they intercept keystrokes system-wide to provide character composition — which makes a code-execution flaw in one a higher-value target than the software’s apparent function suggests. A remote attacker does not need the victim to open a malicious document or run an installer if the input method software itself contains the execution path.
The severity case for upgrading does not depend on the VulnCheck exploitation report or on resolving the vendor-attribution question: NVD and CVE.org agree independently that this is remote code execution via biz_helper.exe, which is sufficient grounds to update to 16.3.0.3498 regardless of catalog status or who is named as the responsible vendor.
Frequently Asked Questions
What is CVE-2026-51990?
A CVSS 9.8 remote code execution vulnerability (CWE-94) in the biz_helper.exe component of Sogou Input Method, corroborated independently by NVD and CVE.org, fixed in version 16.3.0.3498.
Is CVE-2026-51990 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 10, 2026. That report is single-sourced within our source data; CISA has not listed this CVE as of our September 19, 2026 ingestion. Treat it as reported exploitation, not confirmed by our own data, though we note both of our disclosure-record sources agree on the underlying vulnerability’s existence and severity.
Who develops Sogou Input Method? Our sources disagree on how to record this. NVD and CVE.org list no vendor for this CVE. VulnCheck’s KEV entry names Tencent, which acquired Sogou Inc. in 2021 and is a plausible attribution, but it is not corroborated by our disclosure-record sources.
Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.
What does “one-click backdoor” mean in the linked research?
That characterization comes from a Gen Digital research blog cited as a reference by both NVD and CVE.org. We link it as the source it is rather than adopting its framing as our own finding; our own analysis is limited to what NVD and CVE.org state directly, which is remote code execution via biz_helper.exe.
Is authentication required to exploit this? No. NVD’s vector records no required privileges and no required user interaction.
Core description (remote code execution via biz_helper.exe) corroborated independently by the National Vulnerability Database record and the CVE.org record for CVE-2026-51990. CVSS score, vector, weakness classification, and fixed version sourced from NVD alone. Vendor attribution conflicts between sources: NVD and CVE.org record none; VulnCheck KEV attributes the product to Tencent. Exploitation status and the September 10, 2026 catalog date are reported by VulnCheck KEV, an authenticated feed with no public per-CVE page to cite. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our ingestion through September 19, 2026. Additional research reference cited by NVD and CVE.org: Gen Digital research blog. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.