# CVE-2026-19380

## Summary

- **CVE ID:** CVE-2026-19380
- **Severity:** MEDIUM
- **CVSS Score:** 4.6 (CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P)
- **CWE:** CWE-911, CWE-664
- **Published:** Aug 10, 2026
- **Last Modified:** Aug 10, 2026

## Description

A vulnerability was identified in Mullvad wireguard.sys 0.10.1. The affected element is the function AdapterState of the component IOCTL Handler. Such manipulation leads to improper update of reference count. Local access is required to approach this attack. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.

## Affected Products

- Mullvad — wireguard.sys (0.10.1)

## References

- [CNA](https://vuldb.com/vuln/387273)
- [CNA](https://vuldb.com/vuln/387273/cti)
- [CNA](https://vuldb.com/cve/CVE-2026-19380)
- [CNA](https://vuldb.com/submit/866726)
- [CNA](https://drive.google.com/file/d/1LN68wxIx_2EI4IBVq13UlP4G1aqyz--x/view?usp=sharing)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.12%
- **EPSS Percentile:** 1.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._