drive.google.comexploit
https://drive.google.com/file/d/1LN68wxIx_2EI4IBVq13UlP4G1aqyz--x/view?usp=sharing CVE-2026-19380
MEDIUM
Mullvad wireguard.sys IOCTL AdapterState reference count
Record summary
CVE-2026-19380 has a selected CVSS score of 4.6 (medium).
Description
A vulnerability was identified in Mullvad wireguard.sys 0.10.1. The affected element is the function AdapterState of the component IOCTL Handler. Such manipulation leads to improper update of reference count. Local access is required to approach this attack. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 10, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
wireguard.sysBrowse Mullvad / wireguard.sys | CVE List | 0.10.1 | affected |
References
6nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-19380 CVE-2026-19380 | CVE Analysis and ReportThird-party advisory
https://vuldb.com/cve/CVE-2026-19380 Submit #866726 | Mullvad wireguard.sys 0.10.1 Denial of ServiceThird-party advisory
https://vuldb.com/submit/866726 VDB-387273 | Mullvad wireguard.sys IOCTL AdapterState reference countvdb entryTechnical description
https://vuldb.com/vuln/387273 VDB-387273 | CTI Indicators (IOB, IOC, IOA)signaturepermissions required
https://vuldb.com/vuln/387273/cti