Vim bug can run code
vim has a CERT-Bund advisory for 2 vulnerabilities in versions before 9.2.0735. A remote, anonymous attacker can exploit multiple vulnerabilities in vim to execute arbitrary program code.
- Severity
- Not scoredNo CVSS score recorded
- Fix
- Fixed in 9.2.0735Fix recorded today
- Affected versions
- before 9.2.0735
- Affects
- vim+4 more
- Exploited
- Not confirmedNo confirmation recorded
How it works
A remote, anonymous attacker can exploit multiple vulnerabilities in vim to execute arbitrary program code.
What to do
Check your vim version. If it is before 9.2.0735, this advisory applies.
Update vim to 9.2.0735 or newer.
Technical details
Affected software: vim, Linux, Sonstiges, UNIX, Windows
A remote, anonymous attacker can exploit multiple vulnerabilities in vim to execute arbitrary program code. The advisory tracks CVE-2026-59856, CVE-2026-59858. In CERT-Bund's CSAF data, affected versions are before 9.2.0735, before 9.2.0736, and the fixed version is 9.2.0735, 9.2.0736. Affected operating systems listed by CERT-Bund: Linux, Sonstiges, UNIX, Windows.
References
- wid.cert-bund.de · wid-sec-w-2026-2115.json technical description
- github.com · GHSA-fh26-8f79-wj97 vendor advisory
- github.com · GHSA-mf92-v4xw-j45x vendor advisory
- ubuntu.com · USN-8541-1 third party advisory
- msrc.microsoft.com · update-guide third party advisory
- lists.opensuse.org · KITIEWVI4YZXCCOUXKMIC7PBIBXINV2F third party advisory
- lists.suse.com · 027765.html third party advisory
- lists.suse.com · 027752.html third party advisory
- lists.suse.com · 027830.html third party advisory
- lists.suse.com · 027838.html third party advisory
- lists.suse.com · 027926.html third party advisory
- lists.suse.com · 027846.html third party advisory
- lists.suse.com · 027931.html third party advisory
- lists.suse.com · 027921.html third party advisory
- lists.suse.com · 027861.html third party advisory
- access.redhat.com · RHSA-2026:47982 third party advisory
- access.redhat.com · RHSA-2026:48703 third party advisory
- linux.oracle.com · ELSA-2026-48650.html third party advisory
- linux.oracle.com · ELSA-2026-47982.html third party advisory
- errata.build.resf.org · RLSA-2026:47982 third party advisory
- linux.oracle.com · ELSA-2026-48703.html third party advisory
- errata.build.resf.org · RLSA-2026:48650 third party advisory
- errata.build.resf.org · RLSA-2026:48703 third party advisory
- access.redhat.com · RHSA-2026:48650 third party advisory
- lists.suse.com · 028106.html third party advisory
- alas.aws.amazon.com · ALAS2-2026-3829.html third party advisory
- access.redhat.com · RHSA-2026:53371 third party advisory
- access.redhat.com · RHSA-2026:54387 third party advisory
- access.redhat.com · RHSA-2026:55431 third party advisory
- access.redhat.com · RHSA-2026:54769 third party advisory
- dell.com · dsa-2026-386-security-update-f third party advisory
- linux.oracle.com · ELSA-2026-66366-0.html third party advisory
- linux.oracle.com · ELSA-2026-66336-0.html third party advisory