CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-13133

unknowncovered by 2 sourcesfirst seen 2026-08-10
A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is loaded via a relative path without a secure DLL search path, allowing a malicious DLL placed in the installer's directory to be loaded ahead of the legitimate System32 copy.

CSIRTS triage

What
The installer insecurely loads Dynamic Link Libraries, allowing DLL injection attacks.
Who is affected
Users running the LINE for Windows installer on Windows systems.
Urgency
Moderate urgency; no active exploitation reported but DLL loading vulnerabilities are commonly exploited in the wild.
Action
Update to a patched version of the LINE for Windows installer once available from LY Corporation.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-13133

Get an email if CVE-2026-13133 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-13133

CVE.org record

Embed the live status

CVE-2026-13133 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-13133 status](https://www.csirts.com/badge/CVE-2026-13133)](https://www.csirts.com/cve/CVE-2026-13133)