Creative Sound Blaster Katana – Multiple Vulnerabilities in Firmware Verification and Bluetooth Authentication
7 October 2026
Multiple vulnerabilities have been discovered in Creative Sound Blaster Katana products. Creative Labs has released firmware updates to address these vulnerabilities. Special thanks to the informer and Creative Labs for coordinating through CSA's Responsible Vulnerability Disclosure Policy.
Background
Creative Sound Blaster Katana is a series of soundbars that support connectivity and device management through Bluetooth and USB.
CVE ID - Description
CVE-2026-55981 | 9.6 (Critical) – A firmware verification vulnerability in Creative Sound Blaster Katana could allow an attacker to modify a legitimate firmware image and upload the modified firmware to an affected device. Successful exploitation could allow the attacker to install malicious firmware and compromise the device.
CVE-2026-63243 | 4.3 (Medium) – An authentication vulnerability in the Bluetooth Low Energy (BLE) implementation of Creative Sound Blaster Katana could allow an attacker within Bluetooth range to connect to an affected device without prior pairing or authentication. Successful exploitation could allow the attacker to modify device settings or upload malicious firmware to compromise the device.
Affected Versions
Sound Blaster Katana V2 (MF8380) versions prior to 1.30.260813.1100
Sound Blaster Katana V2X (MF8400) versions prior to 1.30.260813.1100
Sound Blaster Katana SE (MF8415) versions prior to 1.30.260813.1110
Mitigation
Creative Labs has released firmware updates to address these vulnerabilities. Users of affected products are advised to update to the latest versions.
Timeline
2026-04-20 – Vendor Disclosure
2026-06-25 – Vendor Patched
2026-08-27 – Public Release
Credit
Discovered by: Mr Rasmus Moorats
References
https://support.creative.com/kb/ShowArticle.aspx?sid=201267&c (opens in new tab)
https://support.creative.com/kb/ShowArticle.aspx?sid=201271&c (opens in new tab)
