← Vulnerability feed

Vulnerability record · CVE-2026-12214 · published 15 June 2026

CVE-2026-12214: A security flaw has been discovered in Qihoo 360 Total Security 6.0.

A security flaw has been discovered in Qihoo 360 Total Security 6.0. This vulnerability affects the function RpcStringBindingComposeW of the component Nucleus Engine Monitoring Logic. Performing a manipulation of the argument NetworkAddr results in protection mechanism failure. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

7.1 CVSS 4.0 High EPSS 0.12% · top 98.2% CWE-693 · CWE-693 Deferred
7.1CVSS 4.0 base score, v2 6.8
0.12%EPSS exploitation probability, 30 days
NoNot in CISA KEV
0Affected product versions listed by NVD
5References
24 Jul 2026Last modified by NVD

Description

A security flaw has been discovered in Qihoo 360 Total Security 6.0. This vulnerability affects the function RpcStringBindingComposeW of the component Nucleus Engine Monitoring Logic. Performing a manipulation of the argument NetworkAddr results in protection mechanism failure. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

References

Track CVE-2026-12214 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-58704Android Cellular Modem improper authorization allows adjacent privilege escalationAndroid's Cellular Modem component contains a logic error that bypasses permission checks, allowing an attacker within radio/adjacent range to escala…KEVEPSS 0.59%analysed4.3CVE-2026-32202Windows Shell protection mechanism failure enables network spoofingWindows Shell contains a protection mechanism failure (CWE-693) that lets an unauthorized attacker perform spoofing over a network. The flaw is rated…KEVEPSS 4.9%analysed9.8CVE-2025-40536SolarWinds Web Help Desk security control bypass allows unauthenticated accessSolarWinds Web Help Desk contains a security control bypass (CWE-693) that lets an unauthenticated attacker reach restricted functionality. It is rat…KEVEPSS 74%analysed8.8CVE-2026-21513Microsoft MSHTML security feature bypass on WindowsCVE-2026-21513 is a protection mechanism failure (CWE-693) in the Microsoft MSHTML Framework that lets an unauthorized attacker bypass a security fea…KEVEPSS 16%analysed8.8CVE-2026-21510Windows Shell protection mechanism failure allows security feature bypassWindows Shell contains a protection mechanism failure (CWE-693) that lets an unauthorized attacker bypass a security feature over a network. The flaw…KEVEPSS 24%analysed7.0CVE-2025-04117-Zip archive extraction fails to propagate Mark-of-the-Web7-Zip does not propagate the Mark-of-the-Web (MOTW) to files extracted from a crafted archive that itself carries MOTW. Because MOTW is what triggers…KEVEPSS 67%analysed7.3CVE-2024-38226Microsoft Publisher security feature bypass via local attackerCVE-2024-38226 is a security feature bypass in Microsoft Publisher, affecting Office 2019, Office Long Term Servicing Channel, and Publisher. The fla…KEVEPSS 2.7%analysed5.4CVE-2024-38217Windows Mark of the Web security feature bypassWindows Mark of the Web (MOTW) fails to properly apply its protection mechanism, allowing the reputation-based warning that normally accompanies file…KEVEPSS 10%analysed

Source: NIST National Vulnerability Database (record CVE-2026-12214), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.