Vim bug can crash services

Published September 11, 2026

vim has a CERT-Bund advisory for CVE-2026-59857 in versions before 9.2.0725. An attacker can exploit a vulnerability in vim to carry out a denial of service attack.

Severity
Not scoredNo CVSS score recorded
Fix
Fixed in 9.2.0725Fix recorded yesterday
Affected versions
before 9.2.0725
Affects
vim+4 more
Exploited
Not confirmedNo confirmation recorded

How it works

An attacker can exploit a vulnerability in vim to carry out a denial of service attack.

What to do

Check your vim version. If it is before 9.2.0725, this advisory applies.

Update vim to 9.2.0725 or newer.

Technical details

Affected software: vim, Linux, Sonstiges, UNIX, Windows

An attacker can exploit a vulnerability in vim to carry out a denial of service attack. The advisory tracks CVE-2026-59857. In CERT-Bund's CSAF data, affected versions are before 9.2.0725, and the fixed version is 9.2.0725. Affected operating systems listed by CERT-Bund: Linux, Sonstiges, UNIX, Windows.