๐Ÿ” CVE Alert

CVE-2026-19380

LOW 2.3

Mullvad wireguard.sys IOCTL AdapterState reference count

CVSS Score
2.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was identified in Mullvad wireguard.sys 0.10.1. The affected element is the function AdapterState of the component IOCTL Handler. Such manipulation leads to improper update of reference count. Local access is required to approach this attack. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.

CWE CWE-911 CWE-664
Vendor mullvad
Product wireguard.sys
Published Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for mullvad wireguard.sys

Be the first to know when new low vulnerabilities affecting mullvad wireguard.sys are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Mullvad / wireguard.sys
0.10.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/387273 vuldb.com: https://vuldb.com/vuln/387273/cti vuldb.com: https://vuldb.com/cve/CVE-2026-19380 vuldb.com: https://vuldb.com/submit/866726 drive.google.com: https://drive.google.com/file/d/1LN68wxIx_2EI4IBVq13UlP4G1aqyz--x/view?usp=sharing

Credits

๐Ÿ” Raulisr00t (VulDB User) VulDB CNA Team