CVE-2026-34714Disclosure(vim / vim)

HIGHCVSS 8.6 · HIGH

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch vim vim systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78CWE-917

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vim

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 17 mentions across 6 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 13 signals
  • Disclosure: 10 classified signals
  • General: 3 classified signals
  • Peaked 4d ago at 6 mentions (2026-03-31); latest day: 1
  • 17 total mentions across 6 days

Affected systems

Vendors
Products
vim

Deep dive

Activity timeline17 mentions / 6d
02356Mentions · 2026-03-30: 3Mentions · 2026-03-31: 6Mentions · 2026-04-01: 5Mentions · 2026-04-06: 1Mentions · 2026-04-09: 1Mentions · 2026-04-15: 1PoC Mentioned / Linked · 2026-03-30: 1PoC Mentioned / Linked · 2026-04-01: 2Exploit Tool / Code · 2026-04-01: 1Active Exploitation · 2026-04-01: 1Patch / Workaround · 2026-03-31: 2Patch / Workaround · 2026-04-01: 3Technical Details · 2026-03-30: 3Technical Details · 2026-03-31: 4Technical Details · 2026-04-01: 4Technical Details · 2026-04-06: 1Technical Details · 2026-04-15: 103-3003-3104-0104-0604-0904-15
Signal classification4 categories
Disclosure
1058.8%
General
317.6%
Patch
317.6%
Active Exploitation
15.9%
Referenced assets14 URLs
Classification over time
DateTotalLabels
2026-03-303
Disclosure2General1
2026-03-316
Disclosure3General1Patch2
2026-04-015
Active Exploitation1Disclosure2General1Patch1
2026-04-061
Disclosure1
2026-04-091
Disclosure1
2026-04-151
Disclosure1
Full discourse17 posts
  • Clandestine@akaclandestine
    Disclosure

    🚨 Critical Security Alert – RCE Vulnerability in Vim (CVE-2026-34714) A high-severity Remote Code Execution (RCE) vulnerability has been identified in the Vim editor. The flaw can be exploited simply by opening a specially crafted file (such as a Markdown file), allowing arbitrary command execution on the victim’s system. 🔗 Official Advisory: https://github.com/vim/vim/security/advisories/GHSA-2gmj-rpqf-pxvh Affected Versions: Vim > 9.1.1391 and < 9.2.0272
Fixed Version: 9.2.0272 Proof of Concept (POC): vim -version # VIM - Vi IMproved 9.2 (2026 Feb 14, compiled Mar 25 2026 22:04:13) wget https://raw.githubusercontent.com/califio/publications/refs/heads/main/MADBugs/vim-vs-emacs-vs-claude/vim.md vim vim.md cat /tmp/calif-vim-rce-poc The vulnerability was discovered by Claude AI using only this extremely simple prompt:
“Someone told me there is a zero-day Remote Code Execution (RCE) vulnerability when opening a file. Find it.” Urgent recommended action: Update Vim to version 9.2.0272 or newer immediately and avoid opening files from untrusted sources. #Cybersecurity #Vim #RCE #ZeroDay #InfoSec #ThreatIntelligence #Vulnerability

    Post summary

    The alert announces a critical RCE flaw in Vim, provides a runnable PoC, references a patch, but does not report active exploitation.

    110147193.8K
    61.1K followersView on X
  • 0x186@doyouusevim
    Disclosure

    0-day найден в VIM… что ж происходит A critical zero-day vulnerability (CVE-2026-34714) was discovered in Vim in late March/early April 2026, allowing Remote Code Execution (RCE) simply by opening a crafted file https://nvd.nist.gov/vuln/detail/CVE-2026-34714

    Post summary

    The post announces the discovery of a critical zero‑day CVE‑2026‑34714 in Vim that allows RCE by opening a crafted file, without detailing any exploit code or active attacks.

    00031286
    293 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Vim の脆弱性 CVE-2026-34714 が FIX:武器化されたファイルによる任意のコマンド実行 https://iototsecnews.jp/2026/03/30/vim-vulnerability-let-attackers-execute-arbitrary-command-via-weaponized-files/ テキストエディタ Vim における、深刻な脆弱性 CVE-2026-34714 (CVSS 8.2) について解説する記事です。この問題の原因は、ファイルごとに固有の設定を読み込む modeline 機能と、危険な命令を隔離して実行する サンドボックス機構の両方に、深刻なプログラム上の不備が重なったことにあります。この攻撃は、特別な設定をしていなくても、悪意のファイルを開くだけで成立してしまうため、非常に影響範囲が広くなっています。ご利用のチームは、ご注意ください。 #CVE202634714 #Vim #Vulnerability

    Post summary

    The post discloses the serious Vim vulnerability CVE‑2026‑34714 that permits arbitrary command execution via weaponized files, detailing the flaw’s mechanisms and CVSS score, without mentioning patches or evidence of ongoing exploitation.

    02010157
    483 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34714 Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tab… https://www.cve.org/CVERecord?id=CVE-2026-34714

    Post summary

    The notice alerts about a code‑execution vulnerability in older Vim releases triggered by a crafted file via "%{expr} injection". No PoC or exploit details are shared, merely the technical nature of the flaw.

    00030322
    57.6K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: High severity vulnerability in #Vim. CVE-2026-34714 CVSS: 8.2. This vulnerability can lead to arbitrary OS command execution when a user opens a crafted file. More info: https://github.com/vim/vim/security/advisories/GHSA-2gmj-rpqf-pxvh #Patch #Patch #Patch

    Post summary

    The text announces a high‑severity patch for CVE‑2026‑34714 in Vim, which could otherwise enable arbitrary OS command execution through crafted files.

    00010249
    7.2K followersView on X
  • Kazuki Omo@omokazuki
    Disclosure

    SIOSセキュリティブログを更新しました。 vimの脆弱性(Critical: CVE-2026-34714) #sios_tech #security #vulnerability #セキュリティ #脆弱性 #linux #vim https://security.sios.jp/vulnerability/vim-security-vulnerability-20260401/

    Post summary

    SIOS has announced the discovery of a critical CVE‑2026‑34714 vulnerability in Vim, noting its severity but not providing PoC, exploit, or patch details.

    00010201
    361 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-34714: Vim (CVSS: 9.2)... Zero-click RCE in Vim via %{expr} injection in tabpanel - every `vim malicious.txt` becomes instant shell access with d... https://zerodaysignal.com/vulnerability/CVE-2026-34714 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A high‑severity, zero‑click RCE vulnerability (CVE‑2026‑34714) in Vim is disclosed; a PoC is linked but no active exploitation, patches, or exploit code are described.

    00001223
    176 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidad en productos Vim ❗ CVE-2026-34714 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-vim-2/ https://t.co/n7nvLZMVZX

    Post summary

    The tweet announces CVE-2026-34714 affecting Vim products, providing a link for additional details but no evidence of exploitation, PoC, or patch information.

    00000127
    6.6K followersView on X
  • CarloX@carloxthebot
    Disclosure

    Claude Code discovered Vim CVE-2026-34714 (RCE, CVSS 9.2) and suggested sandbox bypasses. AI now finds zero-days faster than human researchers. Vim maintainers refused patches. Update to 9.2.0272. Enterprises: prepare for AI-discovered vulnerabilities as standard. #Security #AI

    Post summary

    The post announces the discovery of a high‑severity RCE vulnerability (CVE‑2026‑34714) in Vim, highlights sandbox bypasses, notes that maintainers have declined patches, and recommends upgrading to version 9.2.0272.

    0000091
    24 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting CVE-2026-34714 to achieve RCE in Vim through malicious %{expr} injections in crafted files. The campaign demonstrates how development tools have become prime targets for initial compromise. Runtime segmentation helps contain post-exploitation lateral movement within cloud environments. #ZeroDay #DevSecOps 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/vim-emacs-2026-remote-code-execution-vulnerabilities

    Post summary

    Attackers are actively exploiting CVE‑2026‑34714 to achieve remote code execution in Vim via malicious %{expr} injections, with a full technical breakdown linked for further detail.

    0000068
    1.9K followersView on X
  • IT関連サイト記事@itit7777
    General

    IT関連サイト記事が更新されました!記事はこちらから⇒ vimの脆弱性(Critical: CVE-2026-34714) https://security.sios.jp/vulnerability/vim-security-vulnerability-20260401/

    Post summary

    The article announces a critical Vim vulnerability (CVE-2026-34714) but provides no further technical, exploit, or mitigation information.

    0000090
    446 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-34714 Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tab… https://www.cve.org/CVERecord?id=CVE-2026-34714 ----- Traducción: CVE-2026-34714 Vim… http://infoflow.cloud`

    Post summary

    CVE‑2026‑34714, affecting Vim before 9.2.0272, enables immediate code execution through "%{expr}" injection when opening crafted files. No PoC, exploit, patch, or active exploitation details are provided.

    0000058
    65 followersView on X
  • wsi@wsi17389634
    General

    @calif_io is it CVE-2026-34714?

    Post summary

    The tweet merely asks whether a specific CVE exists, providing no additional context or details.

    00000593
    12 followersView on X
  • flat/京山和将@昼夢堂@flat_ff
    Patch

    https://feedly.com/cve/CVE-2026-34714 Mitigationによると、vimで不審なファイルを開かない、別のエディタを使うくらいがせいぜいか。早めに更新しないと。

    Post summary

    The post provides mitigation guidance for CVE‑2026‑34714, urging users to avoid opening suspicious files in Vim, use a different editor, and update promptly.

    00000121
    1.5K followersView on X
  • Fomalhaut Weisszwerg@FmtWeisszwerg
    Patch

    ファイルを開くだけで任意コードが実行されてしまう vim の脆弱性 CVE-2026-34714 ですが、tabpanel を無効にすることで影響を防ぐことができます https://www.security-next.com/182763

    Post summary

    CVE-2026-34714 is a Vim vulnerability that allows arbitrary code execution when opening a file; disabling the tabpanel mitigates the issue, with no evidence of active exploitation or false positives.

    00000275
    659 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-34714: CRITICAL] Critical vulnerability in Vim &lt; 9.2.0272 allows code execution upon opening a malicious file due to %{expr} injection in tabpanel without P_MLE. #cybersecurity#cve,CVE-2026-34714,#cybersecurity https://cvefind.com/CVE-2026-34714

    Post summary

    The tweet announces a critical Vim vulnerability that enables code execution through an expression injection in tabpanel when opening a malicious file, providing affected versions but no PoC, exploit, or patch details.

    00000117
    608 followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🔴 CVE-2026-34714 - Critical Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE. https://www.thehackerwire.com/vulnerability/CVE-2026-34714/ https://t.co/GCGlLBeLV4

    Post summary

    The tweet describes a critical code‑execution vulnerability in older Vim versions, noting injection via crafted files, but provides no PoC, exploit, patch, or active exploitation evidence.

    00000109
    158 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvimvim---

Explore more