CVE-2026-20502: High severity Microsoft vdec vulnerability
Published Sep 7, 2026
·Updated
In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9196.
Affected Software
107 affected components
Microsoft vdec
All of the following
MediaTek Mt2718 Firmware
MediaTek Mt2718
All of the following
MediaTek Mt6580 Firmware
MediaTek Mt6580
All of the following
MediaTek Mt6739 Firmware
MediaTek Mt6739
All of the following
MediaTek Mt6761 Firmware
MediaTek Mt6761
All of the following
MediaTek Mt6765 Firmware
MediaTek Mt6765
All of the following
MediaTek Mt6768 Firmware
MediaTek Mt6768
All of the following
MediaTek Mt6769 Firmware
MediaTek Mt6769
All of the following
MediaTek Mt6779 Firmware
MediaTek Mt6779
All of the following
MediaTek Mt6781 Firmware
MediaTek Mt6781
All of the following
MediaTek Mt6785 Firmware
MediaTek Mt6785
All of the following
MediaTek Mt6789 Firmware
MediaTek Mt6789
All of the following
MediaTek Mt6833 Firmware
MediaTek Mt6833
All of the following
MediaTek Mt6835 Firmware
MediaTek Mt6835
All of the following
MediaTek Mt6853 Firmware
MediaTek Mt6853
All of the following
MediaTek Mt6855 Firmware
MediaTek Mt6855
All of the following
MediaTek Mt6858 Firmware
MediaTek Mt6858
All of the following
MediaTek Mt6873 Firmware
MediaTek Mt6873
All of the following
MediaTek Mt6877 Firmware
MediaTek Mt6877
All of the following
MediaTek Mt6878 Firmware
MediaTek Mt6878
All of the following
MediaTek Mt6879 Firmware
MediaTek Mt6879
All of the following
MediaTek Mt6881 Firmware
MediaTek Mt6881
All of the following
MediaTek Mt6883 Firmware
MediaTek Mt6883
All of the following
MediaTek Mt6885 Firmware
MediaTek Mt6885
All of the following
MediaTek Mt6886 Firmware
MediaTek Mt6886
All of the following
MediaTek Mt6889 Firmware
MediaTek Mt6889
All of the following
MediaTek Mt6893 Firmware
MediaTek Mt6893
All of the following
MediaTek Mt6895 Firmware
MediaTek Mt6895
All of the following
MediaTek Mt6897 Firmware
MediaTek Mt6897
All of the following
MediaTek Mt6899 Firmware
MediaTek Mt6899
All of the following
MediaTek Mt6983 Firmware
MediaTek Mt6983
All of the following
MediaTek Mt6985 Firmware
MediaTek Mt6985
All of the following
MediaTek Mt6989 Firmware
MediaTek Mt6989
All of the following
MediaTek Mt6991 Firmware
MediaTek Mt6991
All of the following
MediaTek Mt6993 Firmware
MediaTek Mt6993
All of the following
MediaTek Mt8126 Firmware
MediaTek Mt8126
All of the following
MediaTek Mt8171 Firmware
MediaTek Mt8171
All of the following
MediaTek Mt8186 Firmware
MediaTek Mt8186
All of the following
MediaTek Mt8188 Firmware
MediaTek Mt8188
All of the following
MediaTek Mt8189 Firmware
MediaTek Mt8189
All of the following
MediaTek Mt8195 Firmware
MediaTek Mt8195
All of the following
MediaTek Mt8196 Firmware
MediaTek Mt8196
All of the following
MediaTek Mt8367 Firmware
MediaTek Mt8367
All of the following
MediaTek Mt8391 Firmware
MediaTek Mt8391
All of the following
MediaTek Mt8395 Firmware
MediaTek Mt8395
All of the following
MediaTek Mt8668 Firmware
MediaTek Mt8668
All of the following
MediaTek Mt8676 Firmware
MediaTek Mt8676
All of the following
MediaTek Mt8678 Firmware
MediaTek Mt8678
All of the following
MediaTek Mt8696 Firmware
MediaTek Mt8696
All of the following
MediaTek Mt8781 Firmware
MediaTek Mt8781
All of the following
MediaTek Mt8788e Firmware
MediaTek Mt8788e
All of the following
MediaTek Mt8792 Firmware
MediaTek Mt8792
All of the following
MediaTek Mt8799 Firmware
MediaTek Mt8799
All of the following
MediaTek Mt8910 Firmware
MediaTek Mt8910
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ALPS11262030
Event History
Sep 7, 2026
CVE Published
via MITRE·01:57 AM
Data Sourced
via MITRE·01:57 AM
DescriptionWeakness
Data Sourced
via NVD·02:17 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
Exploitation is local and can lead to escalation of privilege. No additional execution privileges are needed, and user interaction is not required.
2
What component is affected and what is the underlying flaw?
The issue affects vdec. It is an out-of-bounds write caused by a missing bounds check.
3
What patch or tracking identifiers should teams use when coordinating remediation?
Use Patch ID ALPS11262030 and Issue ID MSV-9196 to identify the fix and track remediation.