Vim bug can run code

Published September 11, 2026

vim has a CERT-Bund advisory for 6 vulnerabilities in versions before 9.2.0073. A local attacker can exploit multiple vulnerabilities in vim to execute arbitrary code, cause a denial-of-service condition, or manipulate data.

Severity
Not scoredNo CVSS score recorded
Fix
Fixed in 9.2.0073Fix recorded today
Affected versions
before 9.2.0073
Affects
vim+3 more
Exploited
Not confirmedNo confirmation recorded

How it works

A local attacker can exploit multiple vulnerabilities in vim to execute arbitrary code, cause a denial-of-service condition, or manipulate data.

What to do

Check your vim version. If it is before 9.2.0073, this advisory applies.

Update vim to 9.2.0073 or newer.

Technical details

Affected software: vim, Sonstiges, UNIX, Windows

A local attacker can exploit multiple vulnerabilities in vim to execute arbitrary code, cause a denial-of-service condition, or manipulate data. The advisory tracks CVE-2026-28417, CVE-2026-28418, CVE-2026-28419, CVE-2026-28420, CVE-2026-28421, CVE-2026-28422. In CERT-Bund's CSAF data, affected versions are before 9.2.0073, before 9.2.0074, before 9.2.0075, before 9.2.0076, and the fixed version is 9.2.0073, 9.2.0074, 9.2.0075, 9.2.0076. Affected operating systems listed by CERT-Bund: Sonstiges, UNIX, Windows.

References