The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMETODAYNEWSFEEDEVENTS
BOOKMARKS
RSS
© 2026 The Circuitry
About UsSourcesContactCorrectionsPrivacy
  • Today
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Fact-check summary

NVD, CVE.org, VulnCheck, and TheHackerWire all confirm the System Informer CVE-2026-107782 local privilege-escalation flaw before v4.0.26241.138.

Sourcing
1source

via NVD

NVD · track record
52Stories
100%Verified
2830d
All sources →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Home/Tech/System Informer before 4.0.26241.138 exposed to local privilege escalation
VERIFIEDBy Xavier Rivera· ·1 min read

System Informer before 4.0.26241.138 exposed to local privilege escalation

Winsiderss System Informer versions through 4.0.26241.138 contain an incorrect authorization flaw that lets local attackers execute code as SYSTEM from any signed process. Vulncheck rates the issue 7.8 and 8.5.

Source:NVD
Post
System Informer before 4.0.26241.138 exposed to local privilege escalation
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
TL;DRAI · 60 sec read

System Informer versions before 4.0.26241.138 contain a local privilege escalation flaw in the phsvc helper service. Incorrect authorization checks let any Authenticode-signed process connect to the SiSvcApiPort ALPC port and create SYSTEM services via PhSvcApiCreateService. CVE-2026-107782 carries CVSS scores of 7.8 and 8.5. Users on earlier builds stay exposed until they update.

A high-severity vulnerability in Winsiderss System Informer allows local attackers to execute code with SYSTEM privileges.

Vulncheck assigns two CVSS scores to the flaw. The organization rates CVE-2026-107782 at 7.8 under its standard assessment and 8.5 under its CNA role. Both scores fall into the HIGH severity category.
Incorrect authorization checks let any Authenticode-signed process connect to the SiSvcApiPort ALPC port.

The vector describes a local attack with low complexity that requires low privileges and no user interaction. Impact covers high confidentiality, integrity, and availability loss.

The flaw sits in the phsvc helper service. Incorrect authorization checks let any Authenticode-signed process connect to the SiSvcApiPort ALPC port. Attackers can load code into a Microsoft-signed binary such as rundll32.exe to reach the port.
From The CircuitryThe Feed — live briefs across tech, all day.See what’s happening →

Once connected, the attacker can invoke PhSvcApiCreateService to create and start a service that runs as SYSTEM. The issue affects every release from version 0 through 4.0.26241.138.
Once connected, the attacker can invoke PhSvcApiCreateService to create and start a service that runs as SYSTEM.

A commit in the public repository addresses the authorization check. The project released version 4.0.26241.138 to close the gap. Users running earlier builds remain exposed until they update.
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
The vulnerability record lists the project repository and advisory for further reference. No other mitigations appear in the published details.
Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Morning Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning.

Two minutes, free forever. What's in The Brief →

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →Follow@thecircuitry.to →
HELP US IMPROVE
From The Circuitry

See what’s happening right now

The Feed runs all day — short, verified briefs the moment they break.

Open the Feed →
From The Circuitry

Follow @thecircuitry_

Every story we publish, as it happens. No noise between.

Follow on X ↗On Bluesky ↗

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
securityvulnerabilitycve
More fromNVD
  • LobsterAI versions 2026.5.27 to 2026.9.23 contain high-severity directory deletion flaw

    Tech · 3h
  • PHPNuxBill through 2025.3.20 hit by CVE-2026-108108 auth bypass

    Tech · 5h
  • Microsoft discloses CVE-2026-83947 in Azure Event Grid

    Tech · 21h
More inTech
  • Modern Warfare 4 DMZ Early Access Opens October 20

    Tech · 4h
  • GlobalFoundries signs $2B TSMC deal for US silicon interposers

    Tech · 17h
  • SpaceX agrees to buy 800 MHz spectrum for Starlink Mobile

    Tech · 20h
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →

MORE IN THIS BEAT

All Tech →
  • Tech· 

    LobsterAI versions 2026.5.27 to 2026.9.23 contain high-severity directory deletion flaw

    Netease-youdao LobsterAI versions 2026.5.27 through 2026.9.23 contain CVE-2026-108156, a high-severity flaw that enables arbitrary directory deletion via a crafted skill's _meta.json file. The vulnerability carries a CVSS score of 7.1 and requires only that a user install the malicious skill.

  • Tech· 

    PHPNuxBill through 2025.3.20 hit by CVE-2026-108108 auth bypass

    PHPNuxBill through 2025.3.20 is affected by CVE-2026-108108, a CVSS 7.1 authentication bypass in RADIUS CHAP verification. Attackers with a valid username can gain network access and consume customer plans using any password.

  • Tech· 

    IBM Security Verify Access: 4 more vulnerabilities disclosed

    IBM has disclosed four more flaws in Security Verify Access and Verify Identity Access, including a code execution bug it rates critical at 9.1 (NVD: 8.8). Versions 10.0 to 10.0.9.2 and 11.0 to 11.0.3 are affected. IBM says to upgrade to 10.0.9.3 or 11.0.3.1.

  • Tech· 

    Microsoft discloses CVE-2026-83947 in Azure Event Grid

    Microsoft has disclosed CVE-2026-83947, a CVSS 7.7 HIGH spoofing vulnerability in Azure Event Grid caused by missing authorization. Microsoft says it has already fully mitigated the cloud-service flaw and customers have nothing to do.

  • Tech· 

    Critical CVE-2026-77900 Hits Microsoft Azure App Service for Linux

    A critical vulnerability CVE-2026-77900 affects Microsoft Azure App Service for Linux with a CVSS score of 9.8. The flaw allows an unauthenticated attacker to execute code over the network. Microsoft says it has already fully mitigated the flaw; no customer action is needed.