CVE-2026-21019 is an improper input validation vulnerability in the FacAtFunction component of Galaxy Watch devices prior to Samsung Security Maintenance Release May 2026 Release 1. Insufficient validation of attacker-controlled input allows a local attacker to trigger arbitrary code execution in a system-privileged context. The flaw affects vulnerable Galaxy Watch builds that have not received the May 2026 SMR fix.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small proof-of-concept for CVE-2026-21019, demonstrating a Kubernetes CronJob time-manipulation abuse scenario rather than a remote software memory-corruption exploit. The repo contains four files: a LICENSE, a README describing the issue, a vulnerable CronJob manifest (`cronjob_vuln.yaml`), and a Python script (`exploit_cronjob_time.py`) that performs the simulated exploit. The YAML defines a CronJob named `backup` scheduled for 02:00 and includes container logic that checks `date +%H` locally before echoing `doing backup`. The Python exploit is minimal and simply invokes `timedatectl set-time "02:00:00"` via `os.system`, illustrating that an attacker with existing node/root access can alter the host clock so the container's time check passes early. There are no network callbacks, C2 endpoints, or remote targets in the code. The main capability is local post-compromise abuse: forcing premature execution of scheduled or time-gated container tasks by manipulating system time. Because it requires prior privileged access and provides only a basic hardcoded action, the repository is best classified as a POC.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.