Any news on 2026 version? I wonder what will be new in it compared to 2025…
Probably will be named 2027.
According to Melih it will be called the 2027 version.
which means that the new version will be released in December 2026, compared to CIS 2025–December 2024
I don’t know why they joined this silly trend of adding a year to the program name in the first place. We’re using Comodo Internet Security 2025 in the year 2026. If this goes on long enough, we may have been using it in years other than 2025 for longer than the year it actually was 2025. Considering Comodo’s trend of extremely long stretches with zero updates, wouldn’t it make sense to just go back to not including a year in the program name?
I just put together a new PC and installed Comodo Firewall only. I haven’t used Ethernet yet, but on WiFi, the Comodo Widget doesn’t show actual download speed. The firewall does ask for permissions on the different programs and yet the Upload does show correctly. But download shows 0 or completely off at 200-300k.
Is there a way to see which adapter the widget is getting it’s data from? The WiFi has wifi 7, 6 and 5 modes.
So COMODO doesn’t really have transparent MITM attack feature?
I already have this. So I’m in in the middle. At least you should block MITM attack if you don’t going to do that.
Microsoft also prefers security and prevention over detection (for example PatchGuard) and Comodo prefers prevention over detection.
CIS provides ARP cache poisoning but this is not enabled by default.
I want to note that this is still an issue and it even occurred on Windows 10 for me now. Fresh installation of Windows with latest updates. This happened on Windows 11 on my laptop (see my other post) and this is now on Windows 10 on a desktop PC. There has to be a way to reproduce this for you!
Maybe the following helps to reproduce the issue…
-
I only installed the Firewall component and unchecked all three checkmarks at the end of the installation.
-
Then I go through the settings and set the following (ignore the Antivirus component, I normally don’t have it installed):
Thanks for bringing this up again but I lost hope they will ever fix this !
To reproduce the issue just uncheck
“Rate applications according to their vendor rating” and CIS stops working !
I reported this issue 1 1/2 years ago and it is still not fixed !!!
CIS is dead as a dodo !
The referenced 0-day vulnerability regarding the firewall driver being crashed by a maliciously crafted IPv6 packet seems to have been fixed last Thursday by version 13.8.2 of Xcitium XCS Agent for Windows: https://forum.xcitium.com/t/release-notes-agents-hotfix-update-june-11-2026/20980. Hopefully CIS will receive the patch as well.
This setting has been around for a long long time and we always warn about it.
This setting should come with a warning both in the manual and when disabling it. When disabling it CIS will no longer trust Microsoft and Comodo files which will bring the system to a grinding halt as noticed. Or it should disable all vendors except Microsoft and Comodo to ensure the keep the system from coming to a grinding halt.
This setting shows the sheer power of CIS being able to isolate or stop untrusted files in their tracks.
Yes, a person can escalate privileges within the system, and this is precisely the critical danger of this type of vulnerability.
Although the most common immediate effect of a malformed packet is a system crash (Blue Screen of Death), this article demonstrates that the flaw can be exploited for Remote Code Execution (RCE) with Kernel (SYSTEM) privileges.
Below, understand how the technical dynamics of this privilege escalation work:
The Escalation Path (From Packet to Kernel Execution)
To go from a simple crash to total system control, the exploitation process follows a precise logic of memory manipulation:
Memory Pool Alignment (Pool Grooming): The attacker sends a sequence of legitimate network packets to organize the Windows kernel memory (the Kernel Pool). The goal is to make the system allocate predictable memory blocks, leaving a specific space immediately after the location where the malicious packet will be processed.
Controlled Overflow: When the packet containing the integer underflow (counting error) is processed by the Inspect.sys driver, the memory copy function (memcpy) attempts to copy more data than the buffer can hold. Instead of simply crashing, the attacker designs the exact size of the packet so that it “overflows” and precisely overwrites the neighboring memory block that was prepared in the previous step.
Execution Stream Hijacking: In this overwritten neighboring block, the attacker corrupts a function pointer (an address that tells the processor what the next instruction to be executed is). They change this address to point to their own malicious code (payload), which has also been injected into memory.
Maximum Privilege Execution: Because the Comodo driver runs at the highest level of the operating system (Ring 0 / Kernel Mode), any code executed through it automatically gains NT AUTHORITY\SYSTEM privileges.
Why is this worse than a local escalation?
In a typical privilege escalation, the attacker usually needs to:
Invade the machine as a regular user (without privileges).
Run a local program to become an administrator.
In this Comodo case, the escalation is remote and direct: the attacker doesn’t need any user account, doesn’t need a password, and doesn’t need to be logged into the machine. They send the packet over the network and, if the exploit works, they instantly go from a “stranger on the network” to the “supreme system administrator.”
The zero day vulnerability found does crash the system but is not capable starting a RCE (Remote Code Execution).
It was stated in the conclusion of the article as linked by @Redstraw:
[quote]If we could get the underflow down to a smaller size, this bug might make for a viable RCE. But because standard network packets are a maximum of 65 KB in size, the absolute maximum amount we can decrement the underflowed size variable by is 65 KB. Which isn’t anywhere near enough to turn a 4 GB kernel pool overflow into something that won’t crash the system.
I totally accept defeat, but at least the journey was fun.[/quote]
For now there is no known RCE for this zero day vulnerability. I hope CIS will soon get a fix like the Xcitium branch just receive.
I always had a problem that NVIDIA Shadowplay didn´t start.
I used it quite a lot.
But the entries in the vendor list prevented it from starting.
I went into the vendor list and deleted the 2 entries for NVIDIA and voila, Shadowplay worked again !
Question is: Why there are entries in the vendor list preventing programs from starting ?
It seems that this page doesn’t list the database information. Where can I download the latest database manually?
Comodo Anti Malware Database Latest Version & Additions 2023
I´m searching for it too !
Thanks for the additional information and explanation of what happens there! Honestly, I fully expected Comodo and MS files to be whitelisted regardless of that setting.
So I agree, it should either do exactly that or there should be a big warning telling users that disabling that setting will break things. (Though in the latter case, one has to wonder why the setting is there in the first place since it should never be toggled, ever.)


