CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-16793

highCVSS 8.8covered by 2 sourcesfirst seen 2026-08-04
An attacker from an adjacent network can exploit multiple vulnerabilities in Lenovo XClarity Orchestrator to disclose information or execute arbitrary operating system commands as a privileged user.

CSIRTS triage

What
Multiple vulnerabilities allow adjacent network attackers to disclose information or execute arbitrary OS commands with privileged user permissions.
Who is affected
Adjacent network attackers targeting Lenovo XClarity Orchestrator instances on internal networks.
Urgency
High priority; adjacent network access enables both information disclosure and privileged code execution.
Action
Apply patches for CVE-2026-16792 and CVE-2026-16793 from Lenovo and restrict network access to XClarity Orchestrator.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-16793

Get an email if CVE-2026-16793 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-16793

CVE.org record

Embed the live status

CVE-2026-16793 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-16793 status](https://www.csirts.com/badge/CVE-2026-16793)](https://www.csirts.com/cve/CVE-2026-16793)