In summary: A high-severity vulnerability (CVSS 8.5) affects Logi Options+, the software that controls Logitech mice and keyboards on hundreds of thousands of Windows workstations in enterprises. It allows a standard user to gain full system privileges on their PC. The patch has been available since late August; the question now is how urgently it should be deployed.
What Happened
Researcher Jake Bolam of AmberWolf Research reported the vulnerability to Logitech in March 2026. Logitech released a patch on August 19, and the technical details were made public on September 14, under the CVE-2026-12518 identifier.
The problem stems from the Logi Options+ update service, which runs with SYSTEM privileges on Windows. It communicates with the application through a channel that any user-launched process can access. The service believes it is communicating with the official Logitech agent, but in reality, it only verifies the identity of the process contacting it—not what that process is asking it to do. A standard user can therefore trick it into loading an installation file from a location of their choice, without the file’s signature being verified. The result: code execution with the highest privileges in Windows, without requiring administrator access, a network connection, or any action on the victim’s part.
The patched versions are 2.7.954611 and 2.7.961922. No active exploits have been reported to date, either by Logitech or by the researchers who issued the alert.
Does this apply to me?
Logi Options+ is preinstalled on a large portion of the Logitech mice, keyboards, and webcams sold in recent years, including the MX series, which is widely used in office environments. If your Windows computers use this software, this applies to you—whether the PC belongs to an executive, an accountant, or a technician.
One thing to understand: this vulnerability cannot be exploited from the Internet. You must already have access—even limited access—to the targeted machine; a standard user account is sufficient. This is precisely what makes it a real risk in a corporate environment: a shared workstation, an intern, an external contractor with temporary access, or malware already present on the machine via a phishing email can all use it as a springboard to take complete control of the machine, disable the antivirus, or establish a permanent presence on it.
What to Do Now
1. Check the version of Logi Options+ installed on your computers (in the application's "About" menu, or through your fleet management tool). Any version earlier than 2.7.954611 or 2.7.961922 must be updated.
2. If you manage your fleet using a centralized deployment tool, push the update to all devices rather than relying on individual automatic updates, which are slower and less reliable on a large scale.
3. Take this opportunity to check who in your company still has local administrator privileges without really needing them: this type of vulnerability is precisely what makes these overly protected accounts dangerous in the event of an initial compromise.
This vulnerability illustrates why not all vulnerabilities are created equal. A remotely exploitable code execution vulnerability that requires no authentication and is being actively exploited warrants a patch within the hour. A local privilege escalation vulnerability with no known exploits and already patched by the vendor should be addressed as part of the regular update cycle: it’s not an absolute emergency, but it shouldn’t be overlooked either. Our article on security maintenance details this triage method.
Not sure about your exposure?
Get an update from an IT Systems expert
A quick assessment of your exposure and the steps you should take. No obligation.
In a nutshell
Logi Options+ contains a vulnerability that allows a standard user to gain system privileges on a Windows PC. The patch has been available since August 19, and no active exploits have been reported to date. This is a good example of why you should apply updates as part of your regular maintenance cycle—without panicking, but without forgetting to do so either.
— Samir Amara, CEO — IT Systèmes
Frequently asked questions
Is this vulnerability being actively exploited? No; neither Logitech nor the researchers who disclosed it have reported any instances of exploitation in real-world conditions to date.
Should I uninstall Logi Options+ in the meantime? No, updating to a fixed version (2.7.954611 or 2.7.961922) is all it takes to fix the problem.






.jpg)