CVE-2026-34982
published 2026-04-06CVE-2026-34982: Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user…
PriorityP347high8.2CVSS 3.1
AVLACLPRNUIRSCCHIHAN
EPSS
0.47%
37.6th percentile
Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a modeline to be executed. Additionally, the `mapset()` function lacks a `check_secure()` call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | vim | < vim 2:9.2.0315-1 (sid) | vim 2:9.2.0315-1 (sid) |
| msrc | azl3_vim_9.2.0240-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_vim_9.2.0240-1_on_cbl_mariner_2.0 | — | — |
| vim | vim | < 9.2.0276 | 9.2.0276 |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
osv8.2HIGH
vendor_debian8.2HIGH
vendor_msrc8.2HIGH
vendor_redhat8.2HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2026-34982: Vim is an open source, command line text editor
osv·2026-04-06·CVSS 8.2
CVE-2026-34982 [HIGH] CVE-2026-34982: Vim is an open source, command line text editor
Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a modeline to be executed. Additionally, the `mapset()` function lacks a `check_secure()` call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue.
Ubuntu
Vim vulnerabilities
vendor_ubuntu·2026-04-13·CVSS 5.5
CVE-2026-34982 [MEDIUM] Vim vulnerabilities
Title: Vim vulnerabilities
Summary: Several security issues were fixed in Vim.
Nathan Mills discovered that Vim could crash when parsing certain regular
expressions. An attacker could possibly use this issue to cause a denial of
service. This issue only affected Ubuntu 24.04 LTS and Ubuntu 25.10
(CVE-2026-32249)
It was discovered that Vim did not properly sanitize user input. An
attacker could possibly use this issue to execute arbitrary commands.
(CVE-2026-33412)
Avishay Matayev discovered that Vim's modeline sandbox could be bypassed
when opening a maliciously-crafted file. An attacker could possibly use
this issue to execute arbitrary commands. This issue only affected Ubuntu
20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 25.10.
(CVE-2026-34982)
Instructions: In general,
Red Hat
vim: arbitrary command execution via modeline sandbox bypass
vendor_redhat·2026-04-06·CVSS 8.2
CVE-2026-34982 [HIGH] CWE-78 vim: arbitrary command execution via modeline sandbox bypass
vim: arbitrary command execution via modeline sandbox bypass
Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a modeline to be executed. Additionally, the `mapset()` function lacks a `check_secure()` call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue.
A flaw was found in Vim. A modeline is used to set specific editor options directly from a text file. However, the `complete`, `guitabtooltip`, `printheader` options and the `mapset` function lack proper security checks, allowing an attacker to bypass restrictions and cause ar
Microsoft
Vim modeline bypass via various options affects Vim < 9.2.0276
vendor_msrc·2026-04-02·CVSS 8.2
CVE-2026-34982 [HIGH] CWE-78 Vim modeline bypass via various options affects Vim < 9.2.0276
Vim modeline bypass via various options affects Vim < 9.2.0276
Mariner: Mariner
GitHub_M: GitHub_M
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Debian
CVE-2026-34982: vim - Vim is an open source, command line text editor. Prior to version 9.2.0276, a mo...
vendor_debian·2026·CVSS 8.2
CVE-2026-34982 [HIGH] CVE-2026-34982: vim - Vim is an open source, command line text editor. Prior to version 9.2.0276, a mo...
Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a modeline to be executed. Additionally, the `mapset()` function lacks a `check_secure()` call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 2:9.2.0315-1)
trixie: open
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: Axios Hack, Chrome 0-Day, Fortinet Exploits, Paragon Spyware and More
blogs_hackernews·2026-04-06
⚡ Weekly Recap: Axios Hack, Chrome 0-Day, Fortinet Exploits, Paragon Spyware and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Axios Hack, Chrome 0-Day, Fortinet Exploits, Paragon Spyware and More
This week had real hits. The key software got tampered with. Active bugs showed up in the tools people use every day. Some attacks didn’t even need much effort because the path was already there.
One weak spot now spreads wider than before. What starts small can reach a lot of systems fast. New bugs, faster use, less time to react.
That’s this week. Read through it.
## ⚡ Threat of the Week
Axios npm Package Compromised by N. Korean Hackers —Threat actors with ties to North Korea seized control of the npm account belonging to the lead m
Wiz
CVE-2026-34714 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-34714 [MEDIUM] CVE-2026-34714 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-34714 :
Vim vulnerability analysis and mitigation
Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.
Source : NVD
## 8.6
Score
Published March 30, 2026
Severity HIGH
CNA Score 9.2
Affected Technologies
Vim
Linux Fedora
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
vim-enhanced-debuginfo
vim-debuginfo
Sources
Alpine 3.23, edge Severity HIGH Has Fix Added at: Apr 02, 2026
Chainguard Has Fix Added at: Mar 31, 2026
Debian 11, 12, 13 Severity CRITICAL No Fix Added
Wiz
CVE-2026-34379 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.1
CVE-2026-34379 [HIGH] CVE-2026-34379 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-34379 :
Linux Red Hat vulnerability analysis and mitigation
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, a misaligned memory write vulnerability exists in LossyDctDecoder_execute() in src/lib/OpenEXRCore/internal_dwa_decoder.h:749. When decoding a DWA or DWAB-compressed EXR file containing a FLOAT-type channel, the decoder performs an in-place HALF→FLOAT conversion by casting an unaligned uint8_t * row pointer to float * and writing through it. Because the row buffer may not be 4-byte aligned, this constitutes undefined behavior under the C standard and crashes immediately on architectures that enforce alignment (ARM, RISC-V, etc.).
Wiz
CVE-2026-28422 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 2.2
CVE-2026-28422 [LOW] CVE-2026-28422 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28422 :
Vim vulnerability analysis and mitigation
build_stl_str_hl()
Source : NVD
## 2.2
Score
Published February 27, 2026
Severity LOW
CNA Score 2.2
Affected Technologies
Vim
Linux Fedora
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
vim-X11-debuginfo
vim-debuginfo
Sources
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.20, 3.21, 3.22 Severity LOW Has Fix Added at: Mar 08, 2026
Alpine 3.23, edge Severity LOW Has Fix Added at: Mar 02, 2026
CBL-Mariner 2.0 Severity LOW Has Fix Added at: Mar 10, 2026
CBL-Mariner 3.0 Severity LOW Has Fix Added at: Mar 13, 2026
Chainguard H
Wiz
CVE-2026-34378 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2026-34378 [MEDIUM] CVE-2026-34378 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-34378 :
Linux Red Hat vulnerability analysis and mitigation
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.4.0 to before 3.4.9, a missing bounds check on the dataWindow attribute in EXR file headers allows an attacker to trigger a signed integer overflow in generic_unpack(). By setting dataWindow.min.x to a large negative value, OpenEXRCore computes an enormous image width, which is later used in a signed integer multiplication that overflows, causing the process to terminate with SIGILL via UBSan. This vulnerability is fixed in 3.4.9.
Source : NVD
## 6.5
Score
Published April 6, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
Linux Red Hat
Has Public E
Wiz
CVE-2026-28419 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-28419 [MEDIUM] CVE-2026-28419 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28419 :
Vim vulnerability analysis and mitigation
Vim is an open source, command line text editor. Prior to version 9.2.0075, a heap-based buffer underflow exists in Vim's Emacs-style tags file parsing logic. When processing a malformed tags file where a delimiter appears at the start of a line, Vim attempts to read memory immediately preceding the allocated buffer. Version 9.2.0075 fixes the issue.
Source : NVD
## 6.6
Score
Published February 27, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
Vim
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
vim-filesystem
vim-X11
Sources
Wiz
CVE-2026-25749 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.6
CVE-2026-25749 [MEDIUM] CVE-2026-25749 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25749 :
Vim vulnerability analysis and mitigation
Vim is an open source, command line text editor. Prior to version 9.1.2132, a heap buffer overflow vulnerability exists in Vim's tag file resolution logic when processing the 'helpfile' option. The vulnerability is located in the get_tagfname() function in src/tag.c. When processing help file tags, Vim copies the user-controlled 'helpfile' option value into a fixed-size heap buffer of MAXPATHL + 1 bytes (typically 4097 bytes) using an unsafe STRCPY() operation without any bounds checking. This issue has been patched in version 9.1.2132.
Source : NVD
## 6.6
Score
Published February 6, 2026
Severity MEDIUM
CNA Score 6.6
Affected Technologies
Vim
Rocky Linux
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Re
Wiz
CVE-2026-5164 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.4
CVE-2026-5164 [HIGH] CVE-2026-5164 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-5164 :
Linux Red Hat vulnerability analysis and mitigation
RhelDoUnMap()
Source : NVD
## 6.7
Score
Published March 30, 2026
Severity MEDIUM
CNA Score 6.7
Affected Technologies
Linux Red Hat
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
virtio-win
Sources
NVD
Red Hat 9, 10 Severity MEDIUM No Fix Added at: Mar 31, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Linux Red Hat vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published dat
Wiz
CVE-2026-28420 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.4
CVE-2026-28420 [MEDIUM] CVE-2026-28420 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28420 :
Vim vulnerability analysis and mitigation
Vim is an open source, command line text editor. Prior to version 9.2.0076, a heap-based buffer overflow WRITE and an out-of-bounds READ exist in Vim's terminal emulator when processing maximum combining characters from Unicode supplementary planes. Version 9.2.0076 fixes the issue.
Source : NVD
## 4.4
Score
Published February 27, 2026
Severity MEDIUM
CNA Score 4.4
Affected Technologies
Vim
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
vim-common
vim-minimal
Sources
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.
Wiz
CVE-2026-5165 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.4
CVE-2026-5165 [HIGH] CVE-2026-5165 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-5165 :
Linux Red Hat vulnerability analysis and mitigation
A flaw was found in virtio-win, specifically within the VirtIO Block (BLK) device. When the device undergoes a reset, it fails to properly manage memory, resulting in a use-after-free vulnerability. This issue could allow a local attacker to corrupt system memory, potentially leading to system instability or unexpected behavior.
Source : NVD
## 6.7
Score
Published March 30, 2026
Severity MEDIUM
CNA Score 6.7
Affected Technologies
Linux Red Hat
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
virtio-win
Sources
NVD
Red Hat 9, 10 Severity MED
Wiz
CVE-2026-34380 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.9
CVE-2026-34380 [MEDIUM] CVE-2026-34380 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-34380 :
Linux Red Hat vulnerability analysis and mitigation
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, a signed integer overflow exists in undo_pxr24_impl() in src/lib/OpenEXRCore/internal_pxr24.c at line 377. The expression (uint64_t)(w * 3) computes w * 3 as a signed 32-bit integer before casting to uint64_t. When w is large, this multiplication constitutes undefined behavior under the C standard. On tested builds (clang/gcc without sanitizers), two's-complement wraparound commonly occurs, and for specific values of w the wrapped result is a small positive integer, which may allow the subsequent bounds check to pass incorrectly.
Wiz
CVE-2026-32249 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-32249 [MEDIUM] CVE-2026-32249 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32249 :
Vim vulnerability analysis and mitigation
Vim is an open source, command line text editor. From 9.1.0011 to before 9.2.0137, Vim's NFA regex compiler, when encountering a collection containing a combining character as the endpoint of a character range (e.g. [0-0\u05bb]), incorrectly emits the composing bytes of that character as separate NFA states. This corrupts the NFA postfix stack, resulting in NFA_START_COLL having a NULL out1 pointer. When nfa_max_width() subsequently traverses the compiled NFA to estimate match width for the look-behind assertion, it dereferences state->out1->out without a NULL check, causing a segmentation fault. This vulnerability is fixed in 9.2.0137.
Source : NVD
## 5.5
Score
Published March 12, 2026
Severity MEDIUM
CNA Score 5.3
A
Wiz
CVE-2026-34588 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.6
CVE-2026-34588 [HIGH] CVE-2026-34588 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-34588 :
Linux Red Hat vulnerability analysis and mitigation
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.1.0 to before 3.2.7, 3.3.9, and 3.4.9, internal_exr_undo_piz() advances the working wavelet pointer with signed 32-bit arithmetic. Because nx, ny, and wcount are int, a crafted EXR file can make this product overflow and wrap. The next channel then decodes from an incorrect address. The wavelet decode path operates in place, so this yields both out-of-bounds reads and out-of-bounds writes. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9.
Source : NVD
## 8.6
Score
Published April 6, 2026
Severity HIGH
CNA Score 8.6
Affected Technologies
Linux Red Hat
Wiz
CVE-2026-24835 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-24835 [HIGH] CVE-2026-24835 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24835 :
Linux Red Hat vulnerability analysis and mitigation
isAccessAllowed()
true
Source : NVD
## 8.8
Score
Published January 28, 2026
Severity HIGH
CNA Score 8.8
Affected Technologies
Linux Red Hat
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 20.7
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
podman-desktop
Sources
NVD
Red Hat 10 Severity MEDIUM No Fix Added at: Jan 30, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Linux Red Hat vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Wiz
CVE-2026-28421 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-28421 [MEDIUM] CVE-2026-28421 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28421 :
Vim vulnerability analysis and mitigation
Vim is an open source, command line text editor. Versions prior to 9.2.0077 have a heap-buffer-overflow and a segmentation fault (SEGV) exist in Vim's swap file recovery logic. Both are caused by unvalidated fields read from crafted pointer blocks within a swap file. Version 9.2.0077 fixes the issue.
Source : NVD
## 7.8
Score
Published February 27, 2026
Severity HIGH
CNA Score 5.3
Affected Technologies
Vim
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
vim-default-editor
xxd
Sources
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17
Wiz
CVE-2026-3234 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.3
CVE-2026-3234 [MEDIUM] CVE-2026-3234 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3234 :
Linux Red Hat vulnerability analysis and mitigation
A flaw was found in mod_proxy_cluster. This vulnerability, a Carriage Return Line Feed (CRLF) injection in the decodeenc() function, allows a remote attacker to bypass input validation. By injecting CRLF sequences into the cluster configuration, an attacker can corrupt the response body of INFO endpoint responses. Exploitation requires network access to the MCMP protocol port, but no authentication is needed.
Source : NVD
## 4.3
Score
Published March 12, 2026
Severity MEDIUM
CNA Score 4.3
Affected Technologies
Linux Red Hat
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 26.8
Exploitation Probability (EPSS) 0.1
Af
Wiz
CVE-2025-35998 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.0
CVE-2025-35998 [HIGH] CVE-2025-35998 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-35998 :
Linux Red Hat vulnerability analysis and mitigation
Missing protection mechanism for alternate hardware interface in the Intel(R) Quick Assist Technology for some Intel(R) Platforms within Ring 0: Kernel may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Source : NVD
## 7
Wiz
CVE-2026-35177 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.1
CVE-2026-35177 [MEDIUM] CVE-2026-35177 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-35177 :
Vim vulnerability analysis and mitigation
Vim is an open source, command line text editor. Prior to 9.2.0280, a path traversal bypass in Vim's zip.vim plugin allows overwriting of arbitrary files when opening specially crafted zip archives, circumventing the previous fix for CVE-2025-53906. This vulnerability is fixed in 9.2.0280.
Source : NVD
## 4.1
Score
Published April 6, 2026
Severity MEDIUM
CNA Score 4.1
Affected Technologies
Vim
Linux Red Hat
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
vim-data
xxd
Sources
NVD
Alpine 3.23, edge Severity MEDIUM Has Fix Added at: Apr 02, 2026
De
Wiz
CVE-2026-26269 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-26269 [MEDIUM] CVE-2026-26269 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-26269 :
Vim vulnerability analysis and mitigation
Vim is an open source, command line text editor. Prior to 9.1.2148, a stack buffer overflow vulnerability exists in Vim's NetBeans integration when processing the specialKeys command, affecting Vim builds that enable and use the NetBeans feature. The Stack buffer overflow exists in special_keys() (in src/netbeans.c). The while (*tok) loop writes two bytes per iteration into a 64-byte stack buffer (keybuf) with no bounds check. A malicious NetBeans server can overflow keybuf with a single specialKeys command. The issue has been fixed as of Vim patch v9.1.2148.
Source : NVD
## 7.5
Score
Published February 13, 2026
Severity HIGH
CNA Score 5.4
Affected Technologies
Vim
Alma Linux
Has Public Exploit No
Has CISA KEV Exp
Wiz
CVE-2026-34589 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.4
CVE-2026-34589 [HIGH] CVE-2026-34589 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-34589 :
Linux Red Hat vulnerability analysis and mitigation
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, the DWA lossy decoder constructs temporary per-component block pointers using signed 32-bit arithmetic. For a large enough width, the calculation overflows and later decoder stores operate on a wrapped pointer outside the allocated rowBlock backing store. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9.
Source : NVD
## 8.4
Score
Published April 6, 2026
Severity HIGH
CNA Score 8.4
Affected Technologies
Linux Red Hat
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Wiz
CVE-2026-34982 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-34982 [MEDIUM] CVE-2026-34982 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-34982 :
Vim vulnerability analysis and mitigation
complete
guitabtooltip
printheader
P_MLE
mapset()
check_secure()
Source : NVD
## 8.2
Score
Published April 6, 2026
Severity HIGH
CNA Score 8.2
Affected Technologies
Vim
Linux Red Hat
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
vim
vim-common
Sources
NVD
Alpine 3.23, edge Severity HIGH Has Fix Added at: Apr 02, 2026
Debian 11, 12, 13, 14 Severity HIGH No Fix Added at: Apr 02, 2026
Echo Severity HIGH No Fix Added at: Apr 02, 2026
Red Hat 6, 7, 8, 9 Severity HIGH No Fix Added at: Apr 06, 2026
Red Hat 10 Severity HIGH No Fix Added at: Ap
Wiz
CVE-2026-33412 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.6
CVE-2026-33412 [MEDIUM] CVE-2026-33412 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-33412 :
Vim vulnerability analysis and mitigation
Vim is an open source, command line text editor. Prior to version 9.2.0202, a command injection vulnerability exists in Vim's glob() function on Unix-like systems. By including a newline character (\n) in a pattern passed to glob(), an attacker may be able to execute arbitrary shell commands. This vulnerability depends on the user's 'shell' setting. This issue has been patched in version 9.2.0202.
Source : NVD
## 7.3
Score
Published March 24, 2026
Severity HIGH
CNA Score 5.6
Affected Technologies
Vim
Linux Fedora
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.9
Exploitation Probability (EPSS) N/A
Affected packages and
Wiz
CVE-2026-24825 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.9
CVE-2026-24825 [MEDIUM] CVE-2026-24825 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24825 :
Linux Red Hat vulnerability analysis and mitigation
Missing Release of Memory after Effective Lifetime vulnerability in ydb-platform ydb (contrib/libs/yajl modules). This vulnerability is associated with program files yail_tree.C.
This issue affects ydb: through 24.4.4.2.
Source : NVD
## 6.9
Score
Published January 27, 2026
Severity MEDIUM
CNA Score 6.9
Affected Technologies
Linux Red Hat
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 19.6
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
yajl
yajl-devel
Sources
NVD
Red Hat 6, 7, 8, 9 Severity MEDIUM No Fix Added at: Feb 02, 2026
## Get a CVE risk assessment
Get a prioritized view of C
Wiz
CVE-2026-32284 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-32284 [HIGH] CVE-2026-32284 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32284 :
Linux Red Hat vulnerability analysis and mitigation
The msgpack decoder fails to properly validate the input buffer length when processing truncated fixext data (format codes 0xd4-0xd8). This can lead to an out-of-bounds read and a runtime panic, allowing a denial of service attack.
Source : NVD
## 7.5
Score
Published March 26, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
Linux Red Hat
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 17.1
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
fence-agents-eaton-snmp
fence-agents-ipmilan
Sources
NVD
GoLang Severity HIGH No Fix Added at: Mar 31, 2026
Red Hat 7, 8, 9, 10 Severity MEDIUM No
Wiz
CVE-2026-28418 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.4
CVE-2026-28418 [MEDIUM] CVE-2026-28418 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28418 :
Vim vulnerability analysis and mitigation
Vim is an open source, command line text editor. Prior to version 9.2.0074, a heap-based buffer overflow out-of-bounds read exists in Vim's Emacs-style tags file parsing logic. When processing a malformed tags file, Vim can be tricked into reading up to 7 bytes beyond the allocated memory boundary. Version 9.2.0074 fixes the issue.
Source : NVD
## 5.5
Score
Published February 27, 2026
Severity MEDIUM
CNA Score 4.4
Affected Technologies
Vim
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
vim-minimal
vim-X11-debuginfo
Sources
Alpine 3.10,
Wiz
CVE-2019-25544 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.9
CVE-2019-25544 [MEDIUM] CVE-2019-25544 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2019-25544 :
Linux Red Hat vulnerability analysis and mitigation
Pidgin 2.13.0 contains a denial of service vulnerability that allows local attackers to crash the application by providing an excessively long username string during account creation. Attackers can input a buffer of 1000 characters in the username field and trigger a crash when joining a chat, causing the application to become unavailable.
Source : NVD
## 6.9
Score
Published March 21, 2026
Severity MEDIUM
CNA Score 6.9
Affected Technologies
Linux Red Hat
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
finch
libpurple-tcl
Sources
NVD
Red
Wiz
CVE-2026-39881 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.6
CVE-2026-39881 [MEDIUM] CVE-2026-39881 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-39881 :
Vim vulnerability analysis and mitigation
Vim is an open source, command line text editor. Prior to 9.2.0316, a command injection vulnerability in Vim's netbeans interface allows a malicious netbeans server to execute arbitrary Ex commands when Vim connects to it, via unsanitized strings in the defineAnnoType and specialKeys protocol messages. This vulnerability is fixed in 9.2.0316.
Source : NVD
## 5
Score
Published April 8, 2026
Severity MEDIUM
CNA Score 5.0
Affected Technologies
Vim
Linux Red Hat
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 33.2
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
cpe:2.3:a:vim:vim
vim
Sources
NVD
Alpine
Wiz
CVE-2026-28417 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.4
CVE-2026-28417 [MEDIUM] CVE-2026-28417 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28417 :
Vim vulnerability analysis and mitigation
netrw
scp://
Source : NVD
## 7.8
Score
Published February 27, 2026
Severity HIGH
CNA Score 4.4
Affected Technologies
Vim
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
vim-X11
vim-common
Sources
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.20, 3.21, 3.22 Severity HIGH Has Fix Added at: Mar 03, 2026
Alpine 3.23, edge Severity HIGH Has Fix Added at: Mar 02, 2026
CBL-Mariner 2.0 Severity MEDIUM Has Fix Added at: Mar 10, 2026
CBL-Mariner 3.0 Severity MEDIUM Has Fix Added at: Mar 13, 2026
Chainguard Has Fix Adde
Bugzilla
CVE-2026-34982 vim: arbitrary command execution via modeline sandbox bypass
bugzilla·2026-04-06·CVSS 8.2
CVE-2026-34982 [HIGH] CVE-2026-34982 vim: arbitrary command execution via modeline sandbox bypass
CVE-2026-34982 vim: arbitrary command execution via modeline sandbox bypass
Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a modeline to be executed. Additionally, the `mapset()` function lacks a `check_secure()` call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue.
Bugzilla
CVE-2026-34982 vim: arbitrary command execution via modeline sandbox bypass [fedora-all]
bugzilla·2026-04-06·CVSS 8.2
CVE-2026-34982 [HIGH] CVE-2026-34982 vim: arbitrary command execution via modeline sandbox bypass [fedora-all]
CVE-2026-34982 vim: arbitrary command execution via modeline sandbox bypass [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-251d74645b (vim-9.2.280-1.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-251d74645b
---
FEDORA-2026-c718defeb6 (vim-9.2.280-1.fc42) has been submitted as an update to Fedora 42.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-c718defeb6
---
In stable in F43 https://bodhi.fedoraproject.org/updates/FEDORA-2026-5f9e9fea3c and in rawhide
https://github.com/vim/vim/commit/75661a66a1db1e1f3f1245c615https://github.com/vim/vim/releases/tag/v9.2.0276https://github.com/vim/vim/security/advisories/GHSA-8h6p-m6gr-mpw9http://www.openwall.com/lists/oss-security/2026/04/01/1https://access.redhat.com/errata/RHSA-2026:11389https://access.redhat.com/errata/RHSA-2026:11509https://access.redhat.com/errata/RHSA-2026:11510https://access.redhat.com/errata/RHSA-2026:19073https://access.redhat.com/errata/RHSA-2026:19224https://access.redhat.com/errata/RHSA-2026:21275https://access.redhat.com/errata/RHSA-2026:22634https://access.redhat.com/errata/RHSA-2026:28049https://access.redhat.com/errata/RHSA-2026:28050https://access.redhat.com/errata/RHSA-2026:28133https://access.redhat.com/errata/RHSA-2026:30078https://access.redhat.com/errata/RHSA-2026:30087https://access.redhat.com/errata/RHSA-2026:30088https://access.redhat.com/errata/RHSA-2026:30089https://access.redhat.com/errata/RHSA-2026:30900https://access.redhat.com/errata/RHSA-2026:33453https://access.redhat.com/errata/RHSA-2026:34476https://access.redhat.com/errata/RHSA-2026:34477https://access.redhat.com/errata/RHSA-2026:36004https://access.redhat.com/errata/RHSA-2026:36005https://access.redhat.com/errata/RHSA-2026:36006https://access.redhat.com/security/cve/CVE-2026-34982https://bugzilla.redhat.com/show_bug.cgi?id=2455400https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34982.json
2026-04-06
Published