CVE-2026-21010 is an improper input validation vulnerability in Samsung Retail Mode affecting Android 14, 15, and 16 prior to SMR Apr-2026 Release 1. The flaw allows a local attacker to supply crafted input that is not properly validated by the Retail Mode component, resulting in the ability to trigger privileged functions. Samsung indicates the issue was remediated by removing unnecessary implementation in the affected component.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small Python proof-of-concept/demo for CVE-2026-21010, illustrating a SIP digest authentication replay flaw. It contains two code files: a vulnerable Flask-based simulator (sip_server_sim.py) and a replay client (exploit_sip_replay.py), plus a README and license. The server exposes POST /call on port 5060 and, when no Authorization header is present, returns a digest challenge with a fixed nonce (abc123). It does not track nonce reuse, so any subsequent request with the same captured Authorization header is accepted. The exploit script uses Python requests to POST to http://localhost:5060/call with a hardcoded captured digest Authorization header containing nonce abc123 and SIP URI sip:alice@example.com. Successful exploitation results in authentication bypass and a 'Call connected' response. The repository is not part of a larger exploit framework and is best classified as an operational PoC/demo of replay-based unauthorized call access rather than a full weaponized exploit.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.