CVE-2026-84696 affects Phison PS3111-S11 SSD controller firmware versions through SBFQT1.3, exposing privileged vendor unique commands (VUCs) over the ATA interface with weak or absent authentication. Attackers can bypass a CRC-16-based unlock handshake or exploit firmware builds that have no VUC lock entirely. Successful exploitation allows reading and writing to controller memory and raw NAND flash storage. This enables persistent implant installation that survives power cycles, making it a severe supply chain and hardware-level threat. The vulnerability requires physical or logical ATA interface access but no elevated OS privileges once interface access is obtained. Proof-of-concept tools and detailed technical research are publicly available on GitHub and researcher blogs. The exposure affects a widely used OEM SSD controller chip found in many consumer and enterprise storage devices. The lack of strong authentication on privileged commands represents a fundamental firmware security design flaw.