Lenovo Lenovo

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Lenovo product.

RSS Feeds for Lenovo security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Lenovo products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Lenovo Sorted by Most Security Vulnerabilities since 2018

Lenovo Xclarity Administrator21 vulnerabilities

Lenovo Vantage13 vulnerabilities

Lenovo Pcmanager12 vulnerabilities

Lenovo App Store8 vulnerabilities

Lenovo System Update7 vulnerabilities

Lenovo Pc Manager6 vulnerabilities

Lenovo Diagnostics5 vulnerabilities

Lenovo Drivers Management5 vulnerabilities

Lenovo V14 G6 Itn Bios4 vulnerabilities

Lenovo V15 G4 Iah Bios4 vulnerabilities

Lenovo Baiying4 vulnerabilities

Lenovo Loq 15arp10e Bios4 vulnerabilities

Lenovo S14 G3 Iap Bios4 vulnerabilities

Lenovo V15 G5 Irl Bios4 vulnerabilities

Lenovo Smart Connect4 vulnerabilities

Lenovo V15 G4 Amn Bios4 vulnerabilities

Lenovo Loq 15iax9e Bios4 vulnerabilities

Lenovo V15 G6 Arp Bios4 vulnerabilities

Lenovo Hardware Scan Plugin4 vulnerabilities

Lenovo Hardwarescan Plugin4 vulnerabilities

Lenovo Yoga 9 14irp8 Bios4 vulnerabilities

Lenovo Ideapad 5 15aba7 Bios4 vulnerabilities

Lenovo Legion 5 15ahp10 Bios4 vulnerabilities

Lenovo Legion 5 15akp10 Bios4 vulnerabilities

Lenovo Legion 5 15aph9 Bios4 vulnerabilities

Lenovo Legion 5 15iax10 Bios4 vulnerabilities

Lenovo Legion 5 15irx10 Bios4 vulnerabilities

Lenovo Legion 5 15irx9 Bios4 vulnerabilities

Lenovo Legion 7 16agp11 Bios4 vulnerabilities

Lenovo Legion 7 16iax10 Bios4 vulnerabilities

Lenovo Legion 9 16irx9 Bios4 vulnerabilities

Lenovo Xclarity Orchestrator3 vulnerabilities

Lenovo Browser3 vulnerabilities

Lenovo Commercial Vantage3 vulnerabilities

Lenovo Software Fix3 vulnerabilities

Lenovo Thinkplus Tu8003 vulnerabilities

Lenovo Filez3 vulnerabilities

Lenovo Thinkplus Fu2003 vulnerabilities

Lenovo Thinkplus Fu1003 vulnerabilities

Lenovo Thinkplus Tsd3033 vulnerabilities

Lenovo Personal Cloud A12 vulnerabilities

By the Year

In 2026 there have been 38 vulnerabilities in Lenovo with an average score of 6.3 out of ten. Last year, in 2025 Lenovo had 26 security vulnerabilities published. That is, 12 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.55




Year Vulnerabilities Average Score
2026 38 6.28
2025 26 6.83
2024 19 6.75
2023 25 7.07
2022 10 6.41
2021 10 6.47
2020 38 6.51
2019 12 7.18
2018 11 7.39

It may take a day or so for new Lenovo vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Lenovo Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-10590 Jul 16, 2026
Lenovo BIOS: Missing Auth Enables WMI SMI Trigger A potential missing authentication vulnerability could allow a local privileged attacker to use WMI commands to arbitrarily trigger a System Management Interrupt handler.
Yoga Pro 7 15iph11 Bios
Ideapad Pro 5 16iph11 Bios
Legion 7 16agp11 Bios
And others...
CVE-2026-10589 Jul 16, 2026
Out-of-bounds Write in Lenovo BIOS Enables Local Privilege Escalation to SMM A potential out of bounds write vulnerability could allow a local privileged attacker to execute code in System Management Mode.
Yoga Pro 7 15iph11 Bios
Ideapad Pro 5 16iph11 Bios
Legion 7 16agp11 Bios
And others...
CVE-2026-10588 Jul 16, 2026
Lenovo BIOS Local Privileged Disclosure: SMRAM Address Leak A potential vulnerability could allow a local privileged attacker to disclose the address of protected System Management Mode memory.
Yoga Pro 7 15iph11 Bios
Ideapad Pro 5 16iph11 Bios
Legion 7 16agp11 Bios
And others...
CVE-2026-10587 Jul 16, 2026
Lenovo Firmware SMM OOB Write Enables Privileged Power Setting Change A potential out-of-bounds write vulnerability could allow a local privileged attacker to modify power management settings in System Management Mode.
Yoga Pro 7 15iph11 Bios
Ideapad Pro 5 16iph11 Bios
Legion 7 16agp11 Bios
And others...
CVE-2026-14371 Jul 16, 2026
Lenovo XClarity 5.1.1 WAC PowerShell Cmd Injection The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vulnerable to Powershell Command Injection when establishing remote PowerShell commands.
Xclarity Integrator Microsoft Windows Admin Center
CVE-2026-13104 Jul 16, 2026
Lenovo App Store Local Auth PrivEsc Arbitrary Code Exec A potential vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code with elevated privileges.
App Store
CVE-2026-13103 Jul 16, 2026
Lenovo App Store Path Traversal Enables Authenticated Code Exec A potential path traversal vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code.
App Store
CVE-2026-9046 Jul 16, 2026
Local LPE via insecure perms in Lenovo App Store (Legion Zone) on Windows A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in the Chinese market, that when installed on a nonsystem partition, could allow a local user to execute arbitrary code.
Legion Zone
App Store
CVE-2026-6511 Jul 16, 2026
Lenovo Smart Connect for Windows Improper Access Control CVE-2026-6511 During an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart Connect for Windows that could allow a local authenticated user to access files owned by a different user on the same system.
Smart Connect
CVE-2025-10238 Jun 10, 2026
Out-of-bounds Write in Lenovo ThinkPad BIOS Lets Privileged User Run SMM Code During an internal security assessment, a potential out-of-bounds write vulnerability was discovered in the BIOS of some ThinkPad products could allow a privileged local user to execute code in System Management Mode (SMM).
X13 Gen 6 Type 21rk 21rl Laptops Thinkpad Bios
X1 Carbon 13th Gen Type 21nx 21ny Laptops Thinkpad Bios
P16v Gen 3 Type 21rs 21rt Laptop Thinkpad Bios
And others...
CVE-2025-10237 Jun 10, 2026
Lenovo ThinkPad EC Firmware Local Privilege Escalation: Memory Read/Write During an internal security assessment, a potential vulnerability was discovered in some ThinkPad embedded controller firmware that could allow a privileged local user to perform arbitrary reads or writes to privileged memory regions.
X13 Gen 6 Type 21rk 21rl Laptops Thinkpad Bios
X1 Carbon 13th Gen Type 21nx 21ny Laptops Thinkpad Bios
P16v Gen 3 Type 21rs 21rt Laptop Thinkpad Bios
And others...
CVE-2026-6090 Jun 10, 2026
Lenovo SmartConnect Auth Bypass: Local Auth User Escalates Privileges Windows A potential authentication bypass was reported in Lenovo Smart Connect for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges.
Smart Connect
CVE-2026-8637 Jun 10, 2026
Uncontrolled Search Path Vulnerability in LanSchool Classic A potential uncontrolled search path vulnerability was reported in the LanSchool Classic client application that could allow a local authenticated user to execute arbitrary code with elevated privileges.
Lanschool Classic
CVE-2026-9045 Jun 10, 2026
Lenovo Accessory&Display Manager LPE via local auth on Windows During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges.
Accessories Display Manager Enterprise
CVE-2026-7516 Jun 10, 2026
Lenovo Android App: Clipboard Overwrite via Browser A vulnerability was identified in the Lenovo Android Application, distributed exclusively on tablets in the Chinese market, that could allow a website visited by the built-in browser to overwrite system clipboard contents.
Application
CVE-2026-6282 May 13, 2026
Lenovo PCCS Path Validation Flaw Allows Authenticated File Access A potential improper file path validation vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user to move or access files belonging to other users on the same device.
Personal Cloud T2s
Personal Cloud T2pro
Personal Cloud X1s
And others...
CVE-2026-6281 May 13, 2026
Privileged Remote Shell Exec in Lenovo Personal Cloud Storage A potential vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user on the local network to execute arbitrary commands on the device.
Personal Cloud T2s
Personal Cloud T2pro
Personal Cloud X1s
And others...
CVE-2026-4145 Apr 15, 2026
Lenovo Software Fix Local Authenticated Privilege Escalation: Arbitrary Code Execution During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.
Software Fix
CVE-2026-4135 Apr 15, 2026
Lenovo Software Fix: Local Auth Arbitrary File Write via Install During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to perform an arbitrary file write with elevated privileges.
Software Fix
CVE-2026-4134 Apr 15, 2026
Lenovo Software Fix Local Auth Elevation via Install RCE During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to execute code with elevated privileges.
Software Fix
CVE-2026-1636 Apr 15, 2026
Lenovo Service Bridge DLL Hijack LPE for Authenticated Users A potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allow a local authenticated user to execute code with elevated privileges.
Service Bridge
CVE-2026-0827 Apr 15, 2026
Lenovo Diagnostics HWScanAddin Arbitrary File Write via Local Auth During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareScanAddin used in Lenovo Vantage that, during installation or when using hardware scan, could allow a local authenticated user to perform an arbitrary file write with elevated privileges.
Diagnostics
Vantage
CVE-2026-2640 Mar 11, 2026
Lenovo PC Manager LPE: Authenticated User can Kill Privileged Proc During an internal security assessment, a potential vulnerability was discovered in Lenovo PC Manager that could allow a local authenticated user to terminate privileged processes.
Pc Manager
CVE-2026-1717 Mar 11, 2026
Lenovo PP System Addin: Local Auth Process Termination via Input Validation An input validation vulnerability was reported in the LenovoProductivitySystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to terminate arbitrary processes with elevated privileges.
Vantage
Baiying
CVE-2026-1716 Mar 11, 2026
Lenovo Vantage DeviceSettingsSystemAddin input val allows lcl reg key delete An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to delete arbitrary registry keys with elevated privileges.
Vantage
Baiying
CVE-2026-1715 Mar 11, 2026
Lenovo Vantage Addin Lets Local Auth'd User Escalate Priv & Modify Reg An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to modify arbitrary registry keys with elevated privileges.
Vantage
Baiying
CVE-2026-1653 Mar 11, 2026
Lenovo Virtual Bus Driver DividebyZero Vulnerability (CVE20261653) A potential divide by zero vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could allow a local authenticated user to cause a Windows blue screen error.
Smart Connect
CVE-2026-1652 Mar 11, 2026
Lenovo Virtual Bus Driver BOF in Smart Connect A potential buffer overflow vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could allow a local authenticated user to corrupt memory and cause a Windows blue screen error.
Smart Connect
CVE-2026-0940 Mar 11, 2026
Lenovo ThinkPad BIOS init flaw CVE-2026-0940 A potential improper initialization vulnerability was reported in the BIOS of some ThinkPads that could allow a local privileged user to modify data and execute arbitrary code.
Thinkpad T14 Gen 5 Bios
Thinkpad P14s Gen 5 Bios
Thinkpad Z13 Gen 2 Bios
And others...
CVE-2026-2368 Mar 11, 2026
Lenovo Filez Improper Cert Validation (CVE-2026-2368) An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to execute arbitrary code.
Filez
CVE-2026-1068 Mar 11, 2026
Lenovo Filez Improper Cert Validation (CVE-2026-1068) An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to obtain sensitive user data from the application.
Filez
CVE-2026-0520 Mar 11, 2026
Lenovo FileZ Android App Authenticated Log File Data Disclosure A potential vulnerability was reported in the Lenovo FileZ Android application that, under certain conditions, could allow a local authenticated user to retrieve some sensitive data stored in a log file.
Filez
CVE-2025-14058 Jan 14, 2026
Lenovo Tablet Auth Bypass: Obsolete Control Center Setting A potential missing authentication vulnerability was reported in some Lenovo Tablets that could allow an unauthorized user with physical access to modify Control Center settings if the device is locked when the "Allow Control Center access when locked" option is disabled.
Tab M11 Tb330fu Tb330xu
Tab K11 Tb330fu
Tab K11 Tb330fup
And others...
CVE-2026-0421 Jan 14, 2026
Lenovo ThinkPad BIOS SecureBoot Disable Vulnerability A potential vulnerability was reported in the BIOS of L13 Gen 6, L13 Gen 6 2-in-1, L14 Gen 6, and L16 Gen 2 ThinkPads which could result in Secure Boot being disabled even when configured as On in the BIOS setup menu. This issue only affects systems where Secure Boot is set to User Mode.
Thinkpad L13 Gen 6 Bios
Thinkpad L13 Gen 6 2 In 1 Bios
Thinkpad L14 Gen 6 Bios
And others...
CVE-2025-13455 Jan 14, 2026
ThinkPlus Cfg Auth Bypass, Enables Untrusted Fingerprint Enrollment A vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to bypass ThinkPlus device authentication and enroll an untrusted fingerprint.
Thinkplus Fu100
Thinkplus Fu200
Thinkplus Tu800
And others...
CVE-2025-13454 Jan 14, 2026
Lenovo ThinkPlus Config Software Local Authenticated Info Disclosure A potential vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to gain access to sensitive device information.
Thinkplus Fu100
Thinkplus Fu200
Thinkplus Tu800
And others...
CVE-2025-13453 Jan 14, 2026
Lenovo ThinkPlus USB Drive Physical Read Vulnerability (CVE-2025-13453) A potential vulnerability was reported in some ThinkPlus USB drives that could allow a user with physical access to read data stored on the drive.
Thinkplus Fu100
Thinkplus Fu200
Thinkplus Tu800
And others...
CVE-2025-13154 Jan 14, 2026
SmartPerformanceAddin LPE via Improper Link Follow in Lenovo Vantage An improper link following vulnerability was reported in the SmartPerformanceAddin for Lenovo Vantage that could allow an authenticated local user to perform an arbitrary file deletion with elevated privileges.
Vantage
CVE-2025-13155 Dec 10, 2025
Lenovo Baiying Client: Improper Permissions Enabling Privilege Escalation An improper permissions vulnerability was reported in Lenovo Baiying Client that could allow a local authenticated user to execute code with elevated privileges.
Baiying Client
CVE-2025-13152 Dec 10, 2025
Lenovo One Client DLL Hijacking (LPE) A potential DLL hijacking vulnerability was reported in Lenovo One Client during an internal security assessment that could allow a local authenticated user to execute code with elevated privileges.
One Client
CVE-2025-12046 Dec 10, 2025
DLL Hijacking in Lenovo App Store & Browser enabling local code exec A DLL hijacking vulnerability was reported in the Lenovo App Store and Lenovo Browser applications that could allow a local authenticated user to execute code with elevated privileges under certain conditions.
App Store
Browser
CVE-2025-12048 Nov 12, 2025
Lenovo Scanner Pro: Arbitrary File Upload RCE Vulnerability An arbitrary file upload vulnerability was reported in the Lenovo Scanner Pro client during an internal security assessment that could allow remote code execution or unauthorized control of the affected system.
Scanner Pro
CVE-2025-12047 Nov 12, 2025
Local Network Disclosure in Lenovo Scanner Pro (CVE-2025-12047) A vulnerability was reported in the Lenovo Scanner pro application during an internal security assessment that, under certain circumstances, could allow an attacker on the same logical network to disclose sensitive user files from the application.
Scanner Pro
CVE-2025-10495 Nov 12, 2025
Lenovo PC Manager/App Store/Browser/Legion Zone RCE via LAN A potential vulnerability was reported in the Lenovo PC Manager, Lenovo App Store, Lenovo Browser, and Lenovo Legion Zone client applications that, under certain conditions, could allow an attacker on the same logical network to execute arbitrary code.
App Store
Pc Manager
Browser
And others...
CVE-2025-8485 Nov 12, 2025
Privileged Escalation via Improper Permissions in Lenovo App Store An improper permissions vulnerability was reported in Lenovo App Store that could allow a local authenticated user to execute code with elevated privileges during installation of an application.
App Store
CVE-2025-8421 Nov 12, 2025
Lenovo Dock Manager Improper Default Permission Log File Redirection An improper default permission vulnerability was reported in Lenovo Dock Manager that, under certain conditions during installation, could allow an authenticated local user to redirect log files with elevated privileges.
Dock Manager
CVE-2025-11193 Nov 03, 2025
Lenovo Tablet Local Authenticated Info Disclosure CVE-2025-11193 A potential vulnerability was reported in some Lenovo Tablets that could allow a local authenticated user or application to gain access to sensitive device specific information.
Tab M11 Tb330fu Tb330xu
Tab K11 Tb330fu Tb330fup Tb330xu Tb330xup
Idea Tab Pro Tb373fu
And others...
CVE-2025-10699 Oct 15, 2025
Lenovo LeCloud client Info Disclosure Vulnerability (CVE-2025-10699) A vulnerability was reported in the Lenovo LeCloud client application that, under certain conditions, could allow information disclosure.
Lecloud Client
CVE-2025-10581 Oct 15, 2025
DLL Hijack in Lenovo PC Manager (CVE-2025-10581) A potential DLL hijacking vulnerability was discovered in the Lenovo PC Manager during an internal security assessment that could allow a local authenticated user to execute code with elevated privileges.
Pc Manager
CVE-2025-9548 Oct 15, 2025
Nullptr Deref in Lenovo Power Mgmt Driver Causes BSOD A potential null pointer dereference vulnerability was reported in the Lenovo Power Management Driver that could allow a local authenticated user to cause a Windows blue screen error.
Power Management Driver
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.