Known Vulnerabilities for products from Lenovo

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Lenovo".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Additional devices specifications by Lenovo can be found at device.report : Lenovo

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-64595 json Not Provided 2026-08-06 2026-08-17
CVE-2026-64100 json Not Provided 2026-07-19 2026-07-19
CVE-2026-63839 json Not Provided 2026-07-19 2026-07-19
CVE-2026-63426 json Not Provided 2026-08-13 2026-08-13
CVE-2026-63425 json Not Provided 2026-08-13 2026-08-13
CVE-2026-63424 json Not Provided 2026-08-13 2026-08-13
CVE-2026-63423 json Not Provided 2026-08-13 2026-08-13
CVE-2026-58583 json Not Provided 2026-07-07 2026-07-21
CVE-2026-53348 json Not Provided 2026-07-01 2026-07-01
CVE-2026-53305 json Not Provided 2026-06-26 2026-06-26
CVE-2026-4145 json During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix that could allow a lo... Not Provided 2026-04-15 2026-08-24
CVE-2026-4135 json During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installa... Not Provided 2026-04-15 2026-08-24
CVE-2026-4134 json During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installa... Not Provided 2026-04-15 2026-08-24
CVE-2026-2640 json During an internal security assessment, a potential vulnerability was discovered in Lenovo PC Manager that could allow a loca... Not Provided 2026-03-11 2026-08-24
CVE-2026-2368 json An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable... Not Provided 2026-03-11 2026-08-19
CVE-2026-1653 json A potential divide by zero vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could allow... Not Provided 2026-03-11 2026-08-20
CVE-2026-1652 json A potential buffer overflow vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could allo... Not Provided 2026-03-11 2026-08-20
CVE-2026-1636 json A potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allow a l... Not Provided 2026-04-15 2026-08-24
CVE-2026-1068 json An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable... Not Provided 2026-03-11 2026-08-19
CVE-2026-0827 json During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareScanAd... Not Provided 2026-04-15 2026-08-24

Known software with vulnerabilities from Lenovo

Type Vendor Product Version
HardwareLenovo130-14ast-
Operating
System
Lenovo130-14ast Firmware-
HardwareLenovo130-14ikb-
Operating
System
Lenovo130-14ikb Firmware-
HardwareLenovo130-15ast-
Operating
System
Lenovo130-15ast Firmware-
HardwareLenovo130-15ikb-
Operating
System
Lenovo130-15ikb Firmware-
HardwareLenovo14iwl-
Operating
System
Lenovo14iwl Firmware-
HardwareLenovo20a7-
Operating
System
Lenovo20a7 Firmware-
HardwareLenovo20a8-
Operating
System
Lenovo20a8 Firmware-
HardwareLenovo20a9-
Operating
System
Lenovo20a9 Firmware-
HardwareLenovo20aa-
Operating
System
Lenovo20aa Firmware-
HardwareLenovo20ab-
Operating
System
Lenovo20ab Firmware-

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report