What it is
CVE-2026-51990 is an unauthenticated vulnerability affecting Tencent / Sogou Sogou Input Method for Windows. An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote attacker to...
Vulnerability report
Sogou Input Method for Windows
Tencent / Sogou / Sogou Input Method for Windows
Decision summary
Direct answers before the deeper technical record.
What it is
CVE-2026-51990 is an unauthenticated vulnerability affecting Tencent / Sogou Sogou Input Method for Windows. An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote attacker to...
Is it exploited?
Yes. Previdian tracks this CVE as a known exploited vulnerability. Confidence is high. Also confirmed by third-party sources.
Who is affected?
Tencent / Sogou / Sogou Input Method for Windows.
What should we do?
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
Overview
An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote attacker to execute arbitrary code via the biz_helper.exe component
Exploitation evidence
Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.
Gen
A trusted third party reported exploitation.
Per-source evidence links for KEV attestations are available through the Previdian Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| Gen First | 2026-09-14 13:33 UTC |
Operational indicators for this CVE are listed under Detection.
Detection
Make the evidence actionable in scanner, SOC, and edge-control workflows.
Request targets and User-Agents available in Pro. Callback host details available in Enterprise.
No scanner integrations recorded yet.
No Previdian virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.
Learn about virtual patches →Operational indicators linked to exploitation of this CVE. IoCs age over time — especially IP addresses.
| Type | Indicator | First Seen | Last Seen | Age | Source |
|---|---|---|---|---|---|
| File hash Stale |
29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63
SHA256 |
2026-04-09 13:37 UTC | 2026-04-09 13:37 UTC | 5 months ago | Source |
| File hash Stale |
749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422e
SHA256 |
2026-04-09 13:37 UTC | 2026-04-09 13:37 UTC | 5 months ago | Source |
| File hash Stale |
d7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a
SHA256 |
2026-04-09 13:37 UTC | 2026-04-09 13:37 UTC | 5 months ago | Source |
| IP Stale |
8.218.50.207
|
2026-04-09 13:36 UTC | 2026-04-09 13:36 UTC | 5 months ago | Source |
| Domain Stale |
mail.uaiubifas.top
|
2026-04-09 13:34 UTC | 2026-04-09 13:34 UTC | 5 months ago | Source |
| Domain Stale |
noht1ng.top
|
2026-04-09 13:34 UTC | 2026-04-09 13:34 UTC | 5 months ago | Source |
Risk and context
CVSS v3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
1.0%
Recent mention · BleepingComputer
Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor. [...]
Read full advisoryTimeline
00:00 UTC
Vulnerability disclosed publicly
13:33 UTC
High-confidence, third-party attested exploitation
00:00 UTC
Identifier reserved by the CNA
13:34 UTC
Indicators of compromise recorded
Pro API
Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
GET /api/v2/pro/kevs/CVE-2026-51990
Free JSON includes basic KEV fields{
"cve_id": "CVE-2026-51990",
"confidence": "High",
"cvss_score": 9.8,
"cvss_estimated": false,
"epss_score": 0.00998,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "attempts": 0, "sensors": 0 }
}