Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Wellbia XIGNCODE3 — XIGNCODE3 xhunter1.sys kernel driver contains a Privilege Escalation Vulnerability
AV AC PR UI S C I A CVSS EPSS %ile KEV
L L L N U H H H 7.8 .0019 9.6 —
AFFECTED
Product Versions Fixed
XIGNCODE3 10.0.10011.16384 – —
TIMELINE
Mar 5 Reserved by certcc
May 11 Published (CNA: certcc)
Aug 5 EXPLOIT PUBLISHED — CVE-2026-3609 (Wellbia XIGNCODE3). Public exploit reference added.
Aug 5 RESCORED — CVE-2026-3609 (Wellbia XIGNCODE3). CVSS 5.3 → 7.8 (NVD).
Description
Wellbia's XIGNCODE3 xhunter1.sys kernel driver, version 10.0.10011.16384 through 2023.12.7.78, privilege escalation vulnerability provides access to the IRP_MJ_WRITE command interface, which allows any user process to request a PROCESS_ALL_ACCESS.
Note: KVE 2023-5589 (https://krcert.or.kr) was initially issued for version 10.0.10011.16384, but the vulnerability was not fully remediated and remains in version 2023.12.7.78.
Lifecycle
Complete event history — 4 events, chronological
| Date | Event | Detail |
| March 5, 2026 | Reserved | Reserved by certcc |
| May 11, 2026 | Published | Published (CNA: certcc) |
| August 5, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-3609 (Wellbia XIGNCODE3). Public exploit reference added. |
| August 5, 2026 | RESCORED | RESCORED — CVE-2026-3609 (Wellbia XIGNCODE3). CVSS 5.3 → 7.8 (NVD). |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Wellbia | XIGNCODE3 | — | 10.0.10011.16384 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-3609 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.