CVE-2026-21385

Confirmed PUBLISHED

Integer Overflow or Wraparound in Graphics

Qualcomm, Inc. · Snapdragon

1 day faster than CISA KEV

Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
7.8 High EPSS 1.1%

At a Glance

Memory corruption while using alignments for memory allocation.

cisa
CVE Published
Mar 02, 2026
Exploitation Reported
Jun 01, 2026
CVSS
7.8 High
EPSS
1.1%
Low complexity No user interaction

Affected Versions

235 version rows · page 10 of 10

Vendor Product Version Status
Qualcomm, Inc.
Snapdragon

WCN7880

Affected
Qualcomm, Inc.
Snapdragon

WCN7881

Affected
Qualcomm, Inc.
Snapdragon

WSA8810

Affected
Qualcomm, Inc.
Snapdragon

WSA8815

Affected
Qualcomm, Inc.
Snapdragon

WSA8830

Affected
Qualcomm, Inc.
Snapdragon

WSA8832

Affected
Qualcomm, Inc.
Snapdragon

WSA8835

Affected
Qualcomm, Inc.
Snapdragon

WSA8840

Affected
Qualcomm, Inc.
Snapdragon

WSA8845

Affected
Qualcomm, Inc.
Snapdragon

WSA8845H

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.