BleepingComputer follow-up assigns CVE-2026-51990 to the Sogou IME flaw behind the GRAYRABBIT backdoor
BleepingComputer's write-up assigns CVE-2026-51990 to the same Tencent Sogou Input Method flaw and GRAYRABBIT backdoor that The Hacker News tied to China-linked UNC3569 two days ago — this reads as a CVE catching up to an already-disclosed campaign, not a new vulnerability or a new actor. Targeting (government, education, and financial orgs across East and Southeast Asia) and the vector (a widely-installed third-party IME) are unchanged from the 09-11 item, so treat this as confirmation rather than escalation. No new action beyond the standing guidance: confirm Sogou IME is current (16.3.0.3498+) if it's present in your environment.