CVE-2026-28417Disclosure(vim / vim)

LOWCVSS 7.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch vim vim systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the `scp://` protocol handler), an attacker can execute arbitrary shell commands with the privileges of the Vim process. Version 9.2.0073 fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-86CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vim

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-03-08)
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
vim

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-02-28: 2Mentions · 2026-03-01: 1Mentions · 2026-03-08: 3Patch / Workaround · 2026-02-28: 1Patch / Workaround · 2026-03-08: 3Technical Details · 2026-02-28: 2Technical Details · 2026-03-08: 102-2803-0103-08
Signal classification2 categories
Disclosure
350.0%
Patch
350.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-282
Disclosure1Patch1
2026-03-011
Disclosure1
2026-03-083
Disclosure1Patch2
Full discourse6 posts
  • Nicolas Krassas@Dinosn
    Disclosure

    Multiple Critical Vulnerabilities in Vim https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-28417

    Post summary

    The text announces multiple critical vulnerabilities in Vim and links to a Microsoft advisory, but provides no further technical or exploit details.

    23027154.4K
    151.8K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    6 CVEs fixed in Vim https://www.openwall.com/lists/oss-security/2026/02/27/ CVE-2026-28417: OS Command Injection in netrw CVE-2026-28418,CVE-2026-28419: Heap Out-of-bounds Reads in Emacs tags parsing CVE-2026-28420: Heap-based Buffer Overflow and OOB Read in :terminal + next tweet

    Post summary

    The post announces the patching of six CVEs in Vim, listing each vulnerability and linking to a security mailing list for more details.

    12053740
    4.4K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    URGENT: ##Fedora 43 Vim users! 🚨 A critical patch just dropped fixing SIX CVEs (CVE-2026-28417 to -28422). Read more: 👉 https://tinyurl.com/yu836bm2 #Security https://t.co/AokjN7SZ2t

    Post summary

    The tweet announces that a critical patch has been released for six CVEs affecting Fedora 43 Vim, but provides no additional technical or exploit details.

    0000052
    1.3K followersView on X
  • geoffrey_gordon_ashbrook@GG_Ashbrook
    Patch

    6 vi/vim CVE security patches today Fedora: CVE-2026-28417 to CVE-2026-28422, two 7.8 high severity (50 years of "hard" bro "work"...empirical spaghetti explosion)

    Post summary

    Fedora has issued security patches covering six vi/vim CVEs (CVE‑2026‑28417 through CVE‑2026‑28422) that are rated with high severity.

    0000036
    85 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-28417 Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled with V… https://www.cve.org/CVERecord?id=CVE-2026-28417

    Post summary

    Vim’s netrw plugin contains an OS command injection vulnerability that is fixed in version 9.2.0073; users should update to this version to remediate the issue.

    00000116
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28417 OS Command Injection in Vim netrw Plugin via Crafted URL Before 9.2.0073 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28417

    Post summary

    The text reports a command injection flaw in Vim’s netrw plugin (before 9.2.0073), providing the vulnerability type but offering no PoC, exploit code, active exploitation evidence, or patch info.

    0000066
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvimvim---

Explore more