CVE detail
CVE-2026-2999
IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary executable files from a remote source and execute them.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 13.9 · diversity 10.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
3 source links · newest first
- https://www.twcert.org.tw/tw/cp-132-10740-b2eb2-1.htmlwww.twcert.org.tw
No excerpt available.
Third Party Advisorywww.twcert.org.twMar 2, 2026, 7:16 AM - https://www.twcert.org.tw/en/cp-139-10741-daed4-2.htmlwww.twcert.org.tw
No excerpt available.
Third Party Advisorywww.twcert.org.twMar 2, 2026, 7:16 AM - https://www.changingtec.com/news_detail.jsp?item_id=348www.changingtec.com
No excerpt available.
Vendor Advisorywww.changingtec.comMar 2, 2026, 7:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-3000CVSS 9.3 · Critical
IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary D…
- CVE-2026-66398CVSS 9.4 · Critical
phpMyFAQ before v4.1.6 contains a remote code execution vulnerability in the configuration API that allows authenticated administrators with CONFIGURATION_EDIT and ATTACHMENT_ADD…
- CVE-2026-50562CVSS 9.3 · Critical
FastGPT is a knowledge-based AI application platform. At commit 22ebfacbb43311e9b73294040ae0eb87390c6bba and earlier, artifacts built from untrusted pull request code in .github/w…
- CVE-2021-47987CVSS 7.7 · High
Parse Server before 4.10.0 was affected by a supply chain incident in which incorrect version tags were pushed to the official repository pointing to an unreviewed personal fork o…
- CVE-2021-47986CVSS 7.7 · High
Parse Server before 4.10.0 contains a supply chain vulnerability where incorrect version tags were pushed to the repository linking to unreviewed code in a personal fork. Attacker…
- CVE-2026-55698CVSS 8.8 · High
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can persist package-manager bootstrap metadata in the first YAML document of pnpm-lock.yaml. Before the patch, direct…