Security Brief/Brief
China-aligned group exploits Tencent Sogou Input Method flaw, deploys GrayRabbit backdoor
Threat actors linked to a China-aligned espionage group are exploiting CVE-2026-51990, a critical vulnerability in Tencent's Sogou Input Method for Windows, to deploy the GrayRabbit backdoor.
BriefPublished 13 September 20261 min read1 linked source · 3 checked factsRevision 4
BleepingComputer reports that threat actors linked to a China-aligned espionage group are exploiting CVE-2026-51990, a critical vulnerability in Tencent's Sogou Input Method for Windows, to deploy the GrayRabbit backdoor.
The exposed group is anyone running Sogou Input Method on Windows. The report names no affected version range and no patch, so there is no vendor fix to point to yet.
For small teams, the practical step available today is to inventory Windows endpoints that carry the input method and watch for a vendor fix.
Our view
Windows users of Sogou Input Method should treat themselves as exposed, but the report leaves the version range and patch status open, so the only concrete step available now is knowing which machines carry the input method.
What the reporting says: BleepingComputer states that threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability, CVE-2026-51990, in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor.