HomeIntelligenceBrief
VULNERABILITY BRIEF 🔴 Critical Vulnerability

Critical RCE Vulnerability (CVE‑2026‑51990) in Tencent Sogou Input Method Used to Deploy GrayRabbit Backdoor

A one‑click remote code execution flaw in Tencent’s Sogou Input Method for Windows (CVE‑2026‑51990) is being leveraged by the UNC3569 group to install the GrayRabbit backdoor. The incident underscores the importance of robust vulnerability‑management and auditable patch evidence for third‑party software.

Verisq™ Intelligence · 📅 September 14, 2026 · 📰 bleepingcomputer.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

Hackers Exploit Critical RCE Flaw in Tencent’s Sogou Input Method (CVE‑2026‑51990) to Deploy GrayRabbit Backdoor

What It Is – A one‑click remote code execution vulnerability (CVE‑2026‑51990) in Tencent’s Sogou Input Method for Windows allows an attacker to run arbitrary code via a crafted sgbiz: URI. The flaw is being actively exploited by the UNC3569 espionage group to install the GrayRabbit modular backdoor.

Exploitability – The vulnerability is confirmed in the wild; a public proof‑of‑concept exists. CVSS is not published, but the vendor classifies it as critical (remote code execution with no user interaction beyond clicking a link).

Affected Products – Tencent Sogou Input Method for Windows (all versions prior to 16.3.0.3498).

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for continuous vulnerability‑management controls that capture discovery, remediation, and verification evidence across third‑party software.
  • Highlights gaps in protocol‑handler validation and webview sandboxing, which are control areas mapped to many frameworks (e.g., NIST CSF, ISO 27001).
  • Provides a concrete example of why enterprises must maintain auditable proof of patch deployment for widely‑installed client applications.

Recommended Actions

  1. Inventory all endpoints running Sogou Input Method and verify version 16.3.0.3498 or later is deployed.
  2. If the product is not required, consider removal to eliminate the attack surface.
  3. Update your vulnerability‑management process to capture protocol‑handler validation as a control evidence point.
  4. Conduct a focused control‑mapping review to ensure patch‑management evidence is continuously collected for third‑party components.

Source: BleepingComputer – Hackers exploit Tencent app flaw to deploy GrayRabbit malware

📰 Original Source
https://www.bleepingcomputer.com/news/security/hackers-exploit-tencent-app-flaw-to-deploy-grayrabbit-malware/

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →