Vim bug can run code

Published September 11, 2026

vim has a CERT-Bund advisory for 2 vulnerabilities in versions before 9.2.0662. An attacker can exploit multiple vulnerabilities in vim to perform a denial of service attack or execute arbitrary code.

Severity
Not scoredNo CVSS score recorded
Fix
Fixed in 9.2.0662Fix recorded yesterday
Affected versions
before 9.2.0662
Affects
vim+4 more
Exploited
Not confirmedNo confirmation recorded

How it works

An attacker can exploit multiple vulnerabilities in vim to perform a denial of service attack or execute arbitrary code.

What to do

Check your vim version. If it is before 9.2.0662, this advisory applies.

Update vim to 9.2.0662 or newer.

Technical details

Affected software: vim, Linux, MacOS X, UNIX, Windows

An attacker can exploit multiple vulnerabilities in vim to perform a denial of service attack or execute arbitrary code. The advisory tracks CVE-2026-55892, CVE-2026-55895. In CERT-Bund's CSAF data, affected versions are before 9.2.0662, before 9.2.0663, and the fixed version is 9.2.0662, 9.2.0663. Affected operating systems listed by CERT-Bund: Linux, MacOS X, UNIX, Windows.