CVE-2026-32635Disclosure(angular / angular_cli)

MEDIUMCVSS 9.0 · CRITICAL

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch angular angular_cli systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-next.3, 21.2.4, 20.3.18, and 19.2.20, a Cross-Site Scripting (XSS) vulnerability has been identified in the Angular runtime and compiler. It occurs when the application uses a security-sensitive attribute (for example href on an anchor tag) together with Angular's ability to internationalize attributes. Enabling internationalization for the sensitive attribute by adding i18n-<attribute> name bypasses Angular's built-in sanitization mechanism, which when combined with a data binding to untrusted user-generated data can allow an attacker to inject a malicious script. This vulnerability is fixed in 22.0.0-next.3, 21.2.4, 20.3.18, and 19.2.20.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • angular_cli

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 21 mentions across 12 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 12 signals
  • Technical details provided in 17 signals
  • Disclosure: 9 classified signals
  • Peaked 7d ago at 4 mentions (2026-03-17); latest day: 2
  • 21 total mentions across 12 days

Affected systems

Vendors
Products
angular_cli

1 version affected across 1 product

Deep dive

Activity timeline21 mentions / 12d
01234Mentions · 2026-03-13: 1Mentions · 2026-03-14: 1Mentions · 2026-03-15: 1Mentions · 2026-03-16: 2Mentions · 2026-03-17: 4Mentions · 2026-03-18: 4Mentions · 2026-03-19: 1Mentions · 2026-03-21: 1Mentions · 2026-03-23: 1Mentions · 2026-03-24: 1Mentions · 2026-05-01: 2Mentions · 2026-05-12: 2Active Exploitation · 2026-03-18: 2Patch / Workaround · 2026-03-15: 1Patch / Workaround · 2026-03-16: 2Patch / Workaround · 2026-03-17: 4Patch / Workaround · 2026-03-18: 2Patch / Workaround · 2026-03-19: 1Patch / Workaround · 2026-03-21: 1Patch / Workaround · 2026-03-24: 1Technical Details · 2026-03-15: 1Technical Details · 2026-03-16: 2Technical Details · 2026-03-17: 4Technical Details · 2026-03-18: 3Technical Details · 2026-03-19: 1Technical Details · 2026-03-21: 1Technical Details · 2026-03-23: 1Technical Details · 2026-03-24: 1Technical Details · 2026-05-01: 2Technical Details · 2026-05-12: 103-1303-1403-1503-1603-1703-1803-1903-2103-2303-2405-0105-12
Signal classification4 categories
Disclosure
942.9%
Patch
838.1%
Active Exploitation
29.5%
General
29.5%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-03-131
Disclosure1
2026-03-141
Disclosure1
2026-03-151
Patch1
2026-03-162
Disclosure1Patch1
2026-03-174
Patch4
2026-03-184
Active Exploitation2Disclosure1General1
2026-03-191
Disclosure1
2026-03-211
Patch1
2026-03-231
Disclosure1
2026-03-241
Patch1
2026-05-012
Disclosure2
2026-05-122
Disclosure1General1
Full discourse20 posts
  • Gray Hats@the_yellow_fall
    Patch

    An 8.6 CVSS Angular XSS vulnerability (CVE-2026-32635) bypasses built-in sanitization via i18n attributes. Patch your web applications immediately. #AngularSecurity #XSS #CVE #WebSecurity #CyberSecurity #InfoSec #Vulnerability #PatchAlert #AppSec https://securityonline.info/translation-trap-high-severity-angular-xss-flaw-cve-2026-32635/ https://t.co/ushprxlnRj

    Post summary

    The text warns of a high‑severity Angular XSS flaw (CVE‑2026‑32635) and urges immediate patching of affected applications.

    04082570
    10.7K followersView on X
  • Emmanuel Nii Okai@engniiokai
    Active Exploitation

    🚨 Cybersecurity right now is wild: – New XSS vuln (CVE-2026-32635) exposing thousands of web apps – Hackers hijacking Microsoft 365 accounts via OAuth abuse – New ransomware (Payload) targeting Windows & ESXi – Data breaches hitting petabyte scale – Critical infrastructure & healthcare under active attack This isn’t “future risk.” This is active battlefield conditions.

    Post summary

    The post announces a new XSS vulnerability (CVE‑2026‑32635) and claims it is being actively exploited, with mentions of ongoing attacks on critical infrastructure and healthcare.

    61040102
    808 followersView on X
  • yousukezan@yousukezan
    Disclosure

    Angularのサニタイズをi18nが無効化してXSS ( CVE-2026-32635 )|BookBold https://zenn.dev/bookbold/articles/1f843ccaa60a5b #zenn

    Post summary

    The article discloses an Angular XSS vulnerability where i18n disables sanitization, identified as CVE-2026-32635.

    010421.0K
    12.1K followersView on X
  • Misbar | مسبار@MisbarSec
    Disclosure

    📌 ثغرة XSS في Angular تعرض آلاف تطبيقات الويب لهجمات XSS تم الكشف عن ثغرة Cross-Site Scripting (XSS) بالغة الخطورة، تحمل المعرف CVE-2026-32635، ضمن إطار عمل Angular واسع الانتشار. تسمح هذه الثغرة للمهاجمين بحقن شيفرات خبيثة، مما يعرض آلاف تطبيقات الويب لخطر الاستغلال والتحكم غير المصرح به بجلسات المستخدمين. يُنصح بشدة بتحديث جميع تطبيقات Angular إلى الإصدارات المصححة لدرء هذه التهديدات وتقليل سطح الهجوم. 🔗 للمزيد: https://cybersecuritynews.com/angular-xss-vulnerability-xss-attacks/

    Post summary

    A new CVE‑2026‑32635 XSS flaw in Angular has been disclosed, with vendors urged to patch affected applications immediately.

    00060882
    71 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CVE: CVE-2026-32635 CVSS: 9 (3.1) — CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    A new critical vulnerability (CVE‑2026‑32635) has been disclosed with detailed CVSS metrics, but no PoC, exploit, or patch information is provided.

    1000034
    210 followersView on X
  • iototsecnews@iototsecnews
    Patch

    Angular の XSS 脆弱性 CVE-2026-32635 が FIX:i18n 属性バインディングとサニタイズ回避 https://iototsecnews.jp/2026/03/17/angular-xss-vulnerability-threatens-thousands-of-web-applications/ 訳者後書:この脆弱性 CVE-2026-32635 の原因は、 Angular が持つ国際化 (i18n) 機能とサニタイズ処理の連携に、予期せぬ死角が生じたことにあります。 Angular は href などの重要な属性に対して、 悪意のスクリプトが入り込まないようにするために、自動的に中身を安全な状態へ整えてくれます。 しかし、 これらの属性に i18n タグを組み合わせて使用すると、 内部のコンパイラやランタイムがサニタイズ処理をスキップしてしまうという不備があります。 その結果として、 開発者が導入した国際化の仕組みが、 攻撃者によるチェック回避とコード実行の経路となっています。ご利用のチームは、ご注意ください。 #Angular #CVE202632635 #Vulnerability

    Post summary

    The post announces a fix for CVE-2026-32635, detailing how Angular’s i18n tags bypass sanitization and lead to XSS, but does not provide any PoC or evidence of active exploitation.

    01000104
    481 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    Angularに高深刻度のXSS 脆弱性(CVE-2026-32635)、早期更新が必要 https://rocket-boys.co.jp/security-measures-lab/angular-high-severity-xss-vulnerability-cve-2026-32635/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    A newly disclosed high‑severity XSS vulnerability in Angular (CVE‑2026‑32635) requires operators to apply a patch or update promptly.

    00010130
    337 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-3342 2 - CVE-2026-4149 3 - CVE-2026-32635 4 - CVE-2025-41237 5 - CVE-2019-17571 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The tweet merely lists the top 5 trending CVEs without providing any further technical details, PoC, exploit information, or patch notes.

    00010169
    1.7K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: XSS vulnerability in #Angular. #CVE-2026-32635 CVSS: 8.6. This XSS vulnerability can lead to session hijacking, data exfil, or unauthorised actions. More info: https://ccb.belgium.be/advisories/warning-xss-vulnerability-angular-patch-immediately #Patch #Patch #Patch

    Post summary

    CVE-2026-32635 is a high‑severity XSS flaw in Angular that can lead to session hijacking and data exfiltration; immediate patching is advised.

    01000276
    7.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32635 Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-next.3, 21.2.4, 20… https://www.cve.org/CVERecord?id=CVE-2026-32635

    Post summary

    This brief notice references a newly disclosed CVE affecting Angular (CVE‑2026‑32635) and lists affected versions, but it provides no details on exploitation, patching, or technical specifics.

    00010138
    56.7K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-32635-angular-angular-cli #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The post only shares a link to a research article about CVE-2026-32635, without providing additional details or confirming exploitability.

    0000025
    210 followersView on X
  • selva@SelvaKtm2
    Disclosure

    Angular XSS Bug CVE-2026-32635 Puts Web Apps at High Risk https://thecybrdef.com/angular-xss-bug-cve-2026-32635/ #CVE202632635 #Angular #XSS #WebSecurity #CyberSecurity #VulnerabilityAlert #AppSec #JavaScriptSecurity #FrontendSecurity #PatchNow #InfoSec #CyberThreat #WebAppSecurity #SecurityUpdate

    Post summary

    The brief announcement highlights a newly disclosed Angular XSS vulnerability (CVE-2026-32635) classified as high risk, with no evidence of PoC, exploitation, or patch details provided.

    0000042
    4 followersView on X
  • cybersecuritypath@cybrsecpath
    Disclosure

    Angular XSS Bug CVE-2026-32635 Puts Web Apps at High Risk https://thecybrdef.com/angular-xss-bug-cve-2026-32635/ #CVE202632635 #Angular #XSS #WebSecurity #CyberSecurity #VulnerabilityAlert #AppSec #JavaScriptSecurity #FrontendSecurity #PatchNow #InfoSec #CyberThreat #WebAppSecurity #SecurityUpdate

    Post summary

    The post announces Angular XSS vulnerability CVE‑2026‑32635, notes its high risk, but offers no PoC, exploit, patch, or active exploitation details.

    0000039
    8 followersView on X
  • kantan.news@KantanNewsX
    Patch

    Angular altyapısında keşfedilen kritik XSS güvenlik açığı (CVE-2026-32635), binlerce web uygulamasını tehdit ediyor. Oturum çalma ve veri sızıntısı riskine karşı sistemlerinizi güncellemeyi veya DomSanitizer kullanmayı unutmayın. Haberin detayı: https://kantan.news/x_article.php?slug=angular-da-kritik-xss-gvenlik-a

    Post summary

    The passage highlights a critical Angular XSS vulnerability and recommends patching or using DomSanitizer as a workaround, but provides no evidence of active exploitation or PoC.

    0000091
    961 followersView on X
  • ARCHIE@archie_sham
    Active Exploitation

    🚨 New vulnerabilities discovered: • Angular XSS flaw (CVE-2026-32635) could expose thousands of web apps • n8n RCE vulnerability (CVSS 9.9) is actively being exploited, with thousands of instances at risk Patch immediately. Monitor systems. Assume exposure. #CyberSecurity

    Post summary

    The post announces an Angular XSS flaw and an n8n RCE that is actively exploited, urging immediate patching and system monitoring.

    0000046
    225 followersView on X
  • Cert-IST@cert_ist
    Patch

    Une faille de type XSS (CVE-2026-32635) a été corrigée dans Angular, permettant à des attaquants de contourner les mécanismes de sécurité et d’injecter du code malveillant dans les applications web. https://tinyurl.com/46kd4tdf

    Post summary

    The post announces that CVE-2026-32635, an XSS flaw in Angular, has been patched, meaning the described attack bypasses no longer applies.

    00000120
    963 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Patch

    🚨 Critical Angular i18n XSS Flaw (#CVE-2026-32635) Puts Thousands of Apps at Risk—Patch Now! + Video https://undercodetesting.com/critical-angular-i18n-xss-flaw-cve-2026-32635-puts-thousands-of-apps-at-risk-patch-now-video/ Educational Purposes!

    Post summary

    The post introduces CVE-2026-32635, an Angular i18n XSS vulnerability, warns of widespread risk, and calls users to install the patch, though it lacks PoC or exploit details.

    0000019
    408 followersView on X
  • HeroDevs@herodevs
    Patch

    🚨 New CVE Alert: CVE-2026-32635 (High Severity XSS in Angular) A newly disclosed vulnerability affects how Angular handles i18n attribute bindings. When security-sensitive attributes like href, src, or action are marked with i18n- for translation, Angular’s internationalization pipeline can bypass the framework’s built-in sanitization — allowing attacker-controlled input to execute JavaScript in a user’s browser. Why this matters: → Low complexity exploit with passive user interaction → Potential for session hijacking, credential theft, and data exfiltration → Triggered by a pattern many Angular apps legitimately use for localization Patch status: ✔️ Fixed in Angular 19.2.20, 20.3.18, and 21.2.4 ✔️ Angular 17 and 18 are EOL and will not receive a community fix If you’re running Angular 17 or 18, the exposure is real and there’s no upstream remediation path. HeroDevs Never-Ending Support (NES) for Angular provides patched, drop-in replacements for EOL Angular versions — including fixes for vulnerabilities like CVE-2026-32635 — so teams can stay secure while planning their migration. #Angular #CVE #AppSec #OpenSourceSecurity #DevSecOps #HeroDevs

    Post summary

    The post announces the CVE-2026-32635 XSS flaw in Angular's i18n pipeline, details its exploitation vector, and highlights available fixes for newer Angular releases as well as drop‑in patches for end‑of‑life versions.

    00000121
    2.7K followersView on X
  • AiSoloStudio@aisolostudio
    Disclosure

    AngularのXSS脆弱性(CVE-2026-32635)— i18n属性バインディングでサニタイズが迂回される問題。v19.2.20以降で修正済み。Adobe CommerceのCVSS 9.1も継続対応を。本日のCVE 5件↓ https://tsumikasane.net/security/daily/2026-03-16/

    Post summary

    The post announces the Angular CVE-2026-32635 XSS vulnerability, notes its technical details, and lists a patch (v19.2.20+) that resolves the issue, with no evidence of active exploitation or false‑positive claims.

    0000076
    3 followersView on X
  • Ali Gamal@AliDevEgy
    Patch

    Critical XSS Vulnerability in Angular Patched Now (v19/v20/v21) A High-severity security vulnerability has been disclosed in Angular  CVE-2026-32635 Affects: compiler/core When you use an i18n- prefix #Angular #WebSecurity #XSS #Frontend #AngularSecurity #CVE

    Post summary

    A high‑severity XSS vulnerability (CVE‑2026‑32635) affecting Angular’s compiler/core module has been disclosed and patched for versions 19 to 21.

    0000055
    58 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appangularangular_cli---
Appangularangular_cli22.0.0--
Appangularangular_cli22.0.0--

Explore more