CVE-2026-28421Disclosure(vim / vim)

LOWCVSS 7.8 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch vim vim systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Vim is an open source, command line text editor. Versions prior to 9.2.0077 have a heap-buffer-overflow and a segmentation fault (SEGV) exist in Vim's swap file recovery logic. Both are caused by unvalidated fields read from crafted pointer blocks within a swap file. Version 9.2.0077 fixes the issue.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-122

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vim

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 2 mentions (2026-02-28); latest day: 2
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
vim

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-02-28: 2Mentions · 2026-03-08: 1Mentions · 2026-04-02: 2PoC Mentioned / Linked · 2026-04-02: 2Patch / Workaround · 2026-04-02: 1Technical Details · 2026-02-28: 2Technical Details · 2026-03-08: 1Technical Details · 2026-04-02: 202-2803-0804-02
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-282
Disclosure2
2026-03-081
Disclosure1
2026-04-022
Disclosure1Patch1
Full discourse5 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Vim CVE-2026-28421: Heap-based Buffer Overflow and Improper Input Validation in Swap File Recovery CVE-2026-28422: Stack-based Buffer Overflow when rendering a statusline with a multi-byte fill character on a very wide terminal

    Post summary

    The post announces two CVE disclosures for Vim, detailing heap- and stack-based buffer overflows that affect swap file recovery and statusline rendering.

    00020321
    4.4K followersView on X
  • Innora.ai@Innora_sg
    Disclosure

    We reported 14+ unfixed (int) truncation heap overflows in Vim — the exact same pattern as CVE-2026-28421, which was patched in only ONE location. Co-maintainer mattn acknowledged it as "theoretically correct as a vulnerability class." Lead maintainer chrisbra's response? Closed the GitHub Security Advisory and said: "Last warning, next time you will be blocked." No fix. No discussion. Just a ban threat to the security researcher. Full writeup: https://medium.com/@engningarchitect/vims-partial-patch-problem-14-heap-overflows-left-behind-after-cve-2026-28421-95c3b6863642?source=friends_link&sk=3893f7983f44d1c4346396336193e817 #infosec #cybersecurity #vim #vulnerability #CVE #responsibleDisclosure

    Post summary

    The post highlights that Vim still contains 14+ unfixed integer truncation heap overflow vulnerabilities, referencing a Medium writeup, and notes the absence of a patch or active exploitation evidence.

    00010119
    5 followersView on X
  • Innora.ai@Innora_sg
    Patch

    CVE-2026-28421 fixed ONE (int) truncation in Vim. 14+ identical heap overflows remain. Maintainer closed the GHSA and threatened to ban us. Swap files, undo files, terminal buffers — all attackable. https://medium.com/@engningarchitect/vims-partial-patch-problem-14-heap-overflows-left-behind-after-cve-2026-28421-95c3b6863642?source=friends_link&sk=3893f7983f44d1c4346396336193e817 #infosec #vim

    Post summary

    CVE‑2026‑28421 has a partial patch addressing one integer truncation bug, but 14 other heap overflows remain attackable; the article linked likely details these vulnerabilities, though no exploit code or active attacks are reported.

    0001078
    5 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28421 Vim is an open source, command line text editor. Versions prior to 9.2.0077 have a heap-buffer-overflow and a segmentation fault (SEGV) exist in Vim's swap file recov… https://www.cve.org/CVERecord?id=CVE-2026-28421

    Post summary

    The CVE details a heap‑buffer‑overflow and SEGV in Vim’s swap file recovery for versions before 9.2.0077.

    00000111
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28421 Heap-Buffer-Overflow and SEGV Vulnerability in Vim Text E... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28421 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet announces CVE-2026-28421, noting a heap buffer overflow and segmentation fault in Vim, and provides links for further vulnerability details.

    0000061
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvimvim---

Explore more