BleepingComputer reports that threat actors linked to a China-aligned espionage group are exploiting CVE-2026-51990, a critical vulnerability in Tencent's Sogou Input Method for Windows, to deploy the GrayRabbit backdoor.

The exposed group is anyone running Sogou Input Method on Windows. The report names no affected version range and no patch, so there is no vendor fix to point to yet.

For small teams, the practical step available today is to inventory Windows endpoints that carry the input method and watch for a vendor fix.