CVE-2026-21385

ENISA EUVD: EUVD-2026-9202 ↗
Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: March 3, 2026 17 articles Published: 2026-03-02

EPSS Score

Source: FIRST.org · 2026-05-23
0.21%
probability
This CVE has a 0.21% probability of being exploited in the next 30 days.
0% Top 43.7th percentile of all CVEs 100%

CVSS v3.1

Source: VulnerabilityLookup (CIRCL)
7.8
HIGH
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

VulnerabilityLookup (CNA)
Memory corruption while using alignments for memory allocation.

Affected Products

Qualcomm, Inc.
Snapdragon
5G Fixed Wireless Access Platform APQ8098 AR8031 AR8035 C-V2X 9150 CSRA6620

Attack Intelligence

Google Project Zero

Patched
March 2, 2026
Reported by
Google Threat Analysis Group

Signal Intelligence

Confidence
92%
EPSS 0.21%
CVSS v3.1 7.8
Mentions 17
Last Seen Mar 18, 2026

CNA Information

CNA Assigner
qualcomm
CNA Title
Integer Overflow or Wraparound in Graphics

Analyst Note

CVE-2026-21385 shows strong confirmation signals with active exploitation documented by multiple authoritative sources including Google Project Zero, CISA advisory notices, and widespread Android patch releases. The HIGH severity rating (CVSS 7.8), memory corruption nature, and evidence of real-world attacks by advanced threat actors provide compelling justification for the CONFIRMED status.

Triage Info

Decided atMar 03, 2026
Published DateMar 02, 2026