BriefPulse Security · Security reporting tied to advisories, affected versions and action. RSS · BriefPulse network
BriefPulse Security

Exposures, incidents and defensive changes for people who have to act.

16 September 2026

Brief

China-aligned group exploits Tencent Sogou Input Method flaw, deploys GrayRabbit backdoor

Threat actors linked to a China-aligned espionage group are exploiting CVE-2026-51990, a critical vulnerability in Tencent's Sogou Input Method for Windows, to deploy the GrayRabbit backdoor.

BleepingComputer reports that threat actors linked to a China-aligned espionage group are exploiting CVE-2026-51990, a critical vulnerability in Tencent's Sogou Input Method for Windows, to deploy the GrayRabbit backdoor.

The exposed group is anyone running Sogou Input Method on Windows. The report names no affected version range and no patch, so there is no vendor fix to point to yet.

For small teams, the practical step available today is to inventory Windows endpoints that carry the input method and watch for a vendor fix.

Our reading

Our view is that Windows users of Sogou Input Method should treat themselves as exposed, but the report leaves the version range and patch status open, so the only concrete step available now is knowing which machines carry the input method.

What to do or watch

Inventory Windows endpoints that have Sogou Input Method installed, since the report names no affected version range or patch. Watch for a vendor fix or clarification on affected versions and patch status.

Source details and supporting facts

Each line is stated by the page named above it.

Stated by BleepingComputer

  • Threat actors linked to a China-aligned espionage group are exploiting CVE-2026-51990.
  • The vulnerability is in Tencent's Sogou Input Method for Windows.
  • The exploitation deploys the GrayRabbit backdoor.

Sources

  1. BleepingComputerText stored 14 September 2026

How this story was checked. Written from the 1 page listed above, stored 14 September 2026; claims checked against that stored text on 14 September 2026.

What that means
  • 3 of 3 reported statements were confirmed against the page that carries them; the rest were removed rather than published.
  • Figures in the text were required to appear in the stored source text: yes. Identifiers: yes.
  • The check reads stored text only: no claim rests on a fresh look that did not happen.
  • Where the reporting was silent, the text says so instead of filling the gap.

More from Security