Lenovo
Lenovo Thinkpad Bios: vulnerabilities and CVEs
Lenovo Thinkpad Bios has 2 published vulnerabilities, 2 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs2
Last 12 months2
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10238 | High (8.4) | 0.12% | — | Jun 10, 2026 | During an internal security assessment, a potential out-of-bounds write vulnerability was discovered in the BIOS of some ThinkPad products could allow a privileged local user to execute code in System Management Mode… |
| CVE-2026-0940 | High (8.4) | 0.13% | — | Mar 11, 2026 | A potential improper initialization vulnerability was reported in the BIOS of some ThinkPads that could allow a local privileged user to modify data and execute arbitrary code. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.
Other products by Lenovo
Xclarity Administrator · 28Thinkcentre M625q Firmware · 28Thinkcentre M75n Firmware · 27Ideacentre G5-14imb05 Firmware · 27V50t-13imb Firmware · 27Ideacentre 5-14iob6 Firmware · 27Ideacentre Gaming 5-14iob6 Firmware · 27Thinkcentre M75t GEN 2 Firmware · 26V30a-22iml Firmware · 26Ideacentre 3-07imb05 Firmware · 26Ideacentre Creator 5-14iob6 Firmware · 26Ideacentre C5-14imb05 Firmware · 26