Zero-Day Exploit Discovered in Avast Antivirus

Zero-Day Exploit Discovered in Avast Antivirus

First seen 3 Sep 2026, 13:36 UTC CyberkendraGbhackers 67.5

Article Content

Browse articles
ThreatCluster

A proof-of-concept exploit named PrettyPrague has been released for a privilege escalation vulnerability in Avast Antivirus, allowing attackers to dump the Windows Security Account Manager (SAM) database and execute commands as NT AUTHORITY\SYSTEM. The exploit affects all versions of Avast Antivirus and potentially other Gen Digital products, including AVG and Norton. The researcher, known as Chaotic Eclipse or MSNightmare, published the exploit on August 30, 2026, and it quickly gained traction on GitHub, reaching 125 stars and 31 forks within 24 hours. Gen Digital has not publicly acknowledged the vulnerability or provided any patches or workarounds. Security professionals are advised to monitor for unusual activity related to the SAM registry hive and rotate local account credentials as a precaution.

Key Points: • PrettyPrague exploit allows full local compromise via Avast Antivirus. • No CVE or patch currently exists for the vulnerability. • Gen Digital has not responded to the exploit's disclosure.

Timeline

2026-08-30
PrettyPrague PoC released
Chaotic Eclipse published the exploit for a privilege escalation vulnerability in Avast Antivirus on GitHub.
Cyberkendra
2026-08-31
GitHub repository gains traction
The PrettyPrague repository reached 125 stars and 31 forks within 24 hours of its release.
Cyberkendra
2026-09-01
CVE-2026-65643 published
CVE-2026-65643 was published for a critical flaw in cPanel, unrelated to the Avast exploit.
Cyberkendra
2026-09-03
Gbhackers report on Avast exploit
Gbhackers published an article detailing the PrettyPrague exploit and its implications for Avast users.
Gbhackers