CVE-2026-36425
57Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.
ssvc Actcvss 6.5epss 0.4%
from disclosure to weapon0 days
Published on NVDJul 16
1st PoCJun 17
VulnCheck+41d
exploitation probability
0.4%top 65% of all CVEs
observed exploitation
yesVulnCheck
3 public exploit(s)
An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user can open the device and send process termination requests without privilege validation.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products
n/a · n/apublic PoCs found — 3
githubgithub.com/redteamfortress/CVE-2026-36425★ 23githubgithub.com/gongchuang1089/EDRKiller★ 1vulncheckvulncheck.com/xdb/40da9cd4386funverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://github.com/redteamfortress/CVE-2026-36425https://www.opswat.com/products/oesis-framework/application-removalhttps://www.virustotal.com/gui/file/07c5209bf83065fe760f4fee4ed2308b0c523671f68ca73a3854c2c8c28c0541https://www.virustotal.com/gui/file/2248347b2ec49f07268a44816ebb6265677093ec277f825de1a76700ab25e3bc