Vim bug can run code

Published September 11, 2026

vim has a CERT-Bund advisory for 2 vulnerabilities in versions before 9.2.0735. A remote, anonymous attacker can exploit multiple vulnerabilities in vim to execute arbitrary program code.

Severity
Not scoredNo CVSS score recorded
Fix
Fixed in 9.2.0735Fix recorded today
Affected versions
before 9.2.0735
Affects
vim+4 more
Exploited
Not confirmedNo confirmation recorded

How it works

A remote, anonymous attacker can exploit multiple vulnerabilities in vim to execute arbitrary program code.

What to do

Check your vim version. If it is before 9.2.0735, this advisory applies.

Update vim to 9.2.0735 or newer.

Technical details

Affected software: vim, Linux, Sonstiges, UNIX, Windows

A remote, anonymous attacker can exploit multiple vulnerabilities in vim to execute arbitrary program code. The advisory tracks CVE-2026-59856, CVE-2026-59858. In CERT-Bund's CSAF data, affected versions are before 9.2.0735, before 9.2.0736, and the fixed version is 9.2.0735, 9.2.0736. Affected operating systems listed by CERT-Bund: Linux, Sonstiges, UNIX, Windows.

References