Gen Digital
Avast Free Antivirus, Avast One, Avast Premium Security, Avast Ultimate, Avast Business Security
Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.
This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.
A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.
CVE-observed version history
| CVE | Published | Affected versions | Fixed version information | Publisher evidence |
|---|---|---|---|---|
| CVE-2026-82964 | 16 Sep 2026 | Avast Free Antivirus, Avast One, Avast Premium Security, Avast Ultimate, Avast Business Security: < 26.8; AVG Antivirus Free, AVG Internet Security, AVG Ultimate: < 26.8; Norton Antivirus Plus, Norton 360 Standard, Norton 360 Deluxe, Norton 360 Advanced: < 26.8 | Gen Digital has released a fix as an automatic micro-update to the sandbox driver. No product upgrade or reinstallation is required, and the product version number does not change.; Because the fix replaces a kernel-mode driver, a device restart is required to load it. Until the device is restarted the previous driver stays active and the system remains vulnerable. The application notifies the user to restart.; * 26.7 release line: fixed driver version 26.7.1021.0; * 26.8 release line: fixed driver version 26.8.1020.0; The update was published for Avast, AVG and Norton on 2026-09-04.; Because the fix is delivered as a driver replacement rather than a product version increment, administrators who need to confirm remediation should verify that the running sandbox driver (aswSnx.sys on Avast, avgSnx.sys on AVG, nllSnx.sys on Norton) is at or above the fixed version after the restart, rather than checking the product version.; Installations on release lines earlier than 26.7 do not receive these micro-updates and remain affected. | Update reference ↗ |
How this record is maintained
The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.