Brief
China-aligned group exploits Tencent Sogou Input Method flaw, deploys GrayRabbit backdoor
Threat actors linked to a China-aligned espionage group are exploiting CVE-2026-51990, a critical vulnerability in Tencent's Sogou Input Method for Windows, to deploy the GrayRabbit backdoor.
BleepingComputer reports that threat actors linked to a China-aligned espionage group are exploiting CVE-2026-51990, a critical vulnerability in Tencent's Sogou Input Method for Windows, to deploy the GrayRabbit backdoor.
The exposed group is anyone running Sogou Input Method on Windows. The report names no affected version range and no patch, so there is no vendor fix to point to yet.
For small teams, the practical step available today is to inventory Windows endpoints that carry the input method and watch for a vendor fix.
Our reading
Our view is that Windows users of Sogou Input Method should treat themselves as exposed, but the report leaves the version range and patch status open, so the only concrete step available now is knowing which machines carry the input method.
What to do or watch
Inventory Windows endpoints that have Sogou Input Method installed, since the report names no affected version range or patch. Watch for a vendor fix or clarification on affected versions and patch status.
Source details and supporting facts
Each line is stated by the page named above it.
Stated by BleepingComputer
- Threat actors linked to a China-aligned espionage group are exploiting CVE-2026-51990.
- The vulnerability is in Tencent's Sogou Input Method for Windows.
- The exploitation deploys the GrayRabbit backdoor.
Sources
- BleepingComputerText stored 14 September 2026
How this story was checked. Written from the 1 page listed above, stored 14 September 2026; claims checked against that stored text on 14 September 2026.
What that means
- 3 of 3 reported statements were confirmed against the page that carries them; the rest were removed rather than published.
- Figures in the text were required to appear in the stored source text: yes. Identifiers: yes.
- The check reads stored text only: no claim rests on a fresh look that did not happen.
- Where the reporting was silent, the text says so instead of filling the gap.
More from Security
Report
Spain's AEPD logs its first report of an AI-agent data breach — unverified, but with a concrete credential warning
Brief
Google releases September 2026 patches for Pixel, fixing actively exploited zero-day
Brief