CVE-2026-0828
Kernel driver vulnerability in Safetica Endpoint Client
Vexday Risk Score
41Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 7.5EPSS 0.5%KEV nãoPoC públicaNuclei —Metasploit —Patch —
Lifecycle
15 Oct 2025Public PoC
26 Jun 2026Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
Kernel driver ProcessMonitorDriver.sys in Safetica's endpoint client x64 , versions 10.5.75.0 and 11.11.4.0, allows unprivileged user to abuse IOCTL path and terminate protected system processes.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
Safetica · Endpoint Clientpublic PoCs found — 2
githubgithub.com/KOSEC-LLC/BYOVD-Research★ 8githubgithub.com/mein-0/cve-2026-0828★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →