CVE-2026-34982Patch(vim / vim)

LOWCVSS 8.2 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch vim vim systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a modeline to be executed. Additionally, the `mapset()` function lacks a `check_secure()` call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vim

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 12 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 9 signals
  • General: 4 classified signals
  • Disclosure: 2 classified signals
  • Peaked 4d ago at 5 mentions (2026-04-02); latest day: 1
  • 12 total mentions across 6 days

Affected systems

Vendors
Products
vim

Deep dive

Activity timeline12 mentions / 6d
01345Mentions · 2026-04-01: 3Mentions · 2026-04-02: 5Mentions · 2026-04-07: 1Mentions · 2026-04-08: 1Mentions · 2026-04-13: 1Mentions · 2026-08-05: 1PoC Mentioned / Linked · 2026-04-02: 1Patch / Workaround · 2026-04-01: 2Patch / Workaround · 2026-04-02: 4Patch / Workaround · 2026-04-13: 1Technical Details · 2026-04-01: 2Technical Details · 2026-04-02: 5Technical Details · 2026-04-07: 1Technical Details · 2026-04-13: 104-0104-0204-0704-0804-1308-05
Signal classification3 categories
Patch
650.0%
General
433.3%
Disclosure
216.7%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-04-013
General1Patch2
2026-04-025
Disclosure2Patch3
2026-04-071
General1
2026-04-081
General1
2026-04-131
Patch1
2026-08-051
General1
Full discourse12 posts
  • Gray Hats@the_yellow_fall
    Patch

    Vim patches a critical 8.2 CVSS RCE (CVE-2026-34982). Malicious "modelines" can bypass sandboxes to execute commands. Update to 9.2.0276 immediately! #Vim #CyberSecurity #RCE #InfoSec #Vulnerability #PatchNow #Linux #SysAdmin #CodeExecution #TechNews https://securityonline.info/vim-rce-vulnerability-cve-2026-34982-modeline-bypass/ https://t.co/ewfzfC3YaG

    Post summary

    The tweet announces a critical RCE vulnerability (CVE-2026-34982) in Vim and urges users to apply the 9.2.0276 patch to address it.

    140113942
    12.3K followersView on X
  • Ryan Al-Zhrani@RyanAlZhrani715
    Patch

    أبرز الحوادث الأخيرة (2026): CVE-2026-34982 (Modeline Sandbox Bypass) → مارس/أبريل 2026 → فتح ملف ملغوم = تنفيذ أوامر. الحل: تحديث 9.2.0276 + set nomodeline CVE-2026-39881 (NetBeans Command Injection) → أبريل 2026 → اتصال بسيرفر خبيث = RCE. الحل: تحديث 9.2.0316

    Post summary

    Vendor released updates for CVE-2026-34982 (Modeline sandbox bypass) and CVE-2026-39881 (NetBeans command injection), both of which allow remote code execution if exploited.

    1001049
    61 followersView on X
  • J. Adly@youssefadly237
    General

    first time I read CVE-2026-34982, I was like who the fuck that uses vim that would open a file that they don't know its source I just realized I use neovim as a pager to neomutt, it still does not affect me, but that could me that someone is using vim as a pager lol

    Post summary

    The text merely references CVE-2026-34982 without providing actionable details, evidence of exploitation, or mitigation information.

    0001059
    287 followersView on X
  • Firmis Labs@FirmisLabs
    General

    CVE-2026-34982 · NIST 8.2/10 https://nvd.nist.gov/vuln/detail/CVE-2026-34982

    Post summary

    The post simply cites the CVE ID, its NIST CVSS score, and a link to the NVD entry, with no discussion of exploitation or mitigation.

    1000022
    1 followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-34982: Vim: Modeline bypass via various options affects Vim < 9.2.0276 https://openwall.com/lists/oss-security/2026/03/31/14 Severity: High A modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file

    Post summary

    The post announces a high‑severity Vim modeline bypass (CVE‑2026‑34982) that permits arbitrary OS command execution on versions before 9.2.0276, providing basic technical details but no exploit, patch, or active‑use information.

    00010219
    4.4K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-34982: Vim Modeline Sandbox Bypass - What It Means for Your Business and How to Respond https://hubs.li/Q04b0qgr0

    Post summary

    The text is a headline about CVE-2026-34982 with no further details or actionable information included.

    0000030
    28 followersView on X
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** Vim Modeline Sandbox Bypass Leading to Arbitrary OS Command Execution 📅 **Timeline:** Disclosure: 2026-04-02, Patch: 2026-03-31 🆔 **CVE-2026-34982** | 📊 CVSS: High 🟠 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** Vim < 9.2.0276 🔧 **Fixed Versions:** 9.2.0276 🫨 **Attack Vectors:** - Local - victim opens a specially crafted file (user interaction required) 📝 **Summary:** A modeline sandbox bypass in Vim lets specially crafted files escape modeline protections and execute arbitrary OS commands as the user who opens the file. This can lead to system compromise, data theft, and lateral movement—update immediately. 📈 **Impact Scope:** Arbitrary OS command execution with the privileges of the user running Vim; potential system compromise, data theft, and lateral movement. 🛡️ **Recommended Actions:** - Update Vim to version 9.2.0276 or later immediately. - Disable modeline temporarily (add "set nomodeline" to local.vimrc). - Do not open files from untrusted sources; scan/validate before opening. - Run editors with least privilege and restrict development workstation access. - Monitor for anomalous command execution and follow vendor advisories. 🪢 **Related Resources:** - https://cybersecuritynews.com/vim-modeline-bypass-vulnerability/ - https://github.com/vim/vim/security/advisories/GHSA-8h6p-m6gr-mpw9 🏷 **Tags:** #Cybersecurity #Vim #RCE

    Post summary

    CVE-2026-34982 is a Vim modeline sandbox bypass that allows arbitrary OS command execution; a patch is available in version 9.2.0276, and disabling modeline is recommended as a workaround.

    0000071
    276 followersView on X
  • Syed Aquib@syedaquib77
    Disclosure

    ⚠️ **Vulnerability Alert:** Vim Modeline Sandbox Bypass Allowing Arbitrary OS Command Execution (CVE-2026-34982) 📅 **Timeline:** Disclosure: Not Available, Patch: Not Available 🆔 **CVE-2026-34982** | 📊 CVSS: Not Available | 📈 EPSS: Not Available% 🛠️ **Exploit Maturity:** Not Available 🫨 **Attack Vectors:** - Opening a specially crafted file containing a malicious modeline (user-opened file) 📝 **Summary:** A malicious modeline in a crafted file can bypass Vim's modeline sandbox and execute arbitrary OS commands with the privileges of the user running Vim. This may enable data access, code execution, or further system compromise depending on user privileges. 📈 **Impact Scope:** Arbitrary operating-system command execution as the user running Vim; potential data access, code execution, and further system compromise depending on user privileges. 🛡️ **Recommended Actions:** - Do not open untrusted files in Vim. - Disable modelines in Vim configuration (e.g., set nomodeline) until a patch is available. - Run editors with least privilege and consider sandboxing or containerizing editing sessions. - Monitor vendor advisories and apply patches when released. - Educate users to avoid opening files from untrusted sources. 🪢 **Related Resources:** - https://cybersecuritynews.com/vim-modeline-bypass-vulnerability/ - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34982 🏷 **Tags:** #Cybersecurity #Vim #CVE2026_34982

    Post summary

    The post announces CVE‑2026‑34982, a Vim modeline sandbox bypass that allows arbitrary OS command execution, and outlines mitigation steps to disable modelines and run Vim with minimal privileges until a vendor patch is released.

    0000062
    276 followersView on X
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** Vim modeline sandbox bypass (arbitrary OS command execution) & Nginx-UI backup-restore tampering 🆔 **CVE-2026-34982** 🆔 **CVE-2026-33026** | 📊 CVSS: 9.1 (CRITICAL 🔴) | 📈 EPSS: 1.67% 🛠️ **Exploit Maturity:** Proof-of-Concept 📂 **Affected Versions:** unspecified Vim versions (modeline sandbox bypass), nginx-ui < 2.3.4 🔧 **Fixed Versions:** (unknown), nginx-ui 2.3.4 🫨 **Attack Vectors:** - Vim: local file modeline crafted to execute OS commands when opened (local user opens file) - Nginx-UI: backup restore tampering via manipulated encrypted backup archives (network-exposed service; requires high privileges) 📝 **Summary:** A Vim modeline sandbox bypass can execute arbitrary OS commands when a crafted file is opened, risking system compromise under the user context. Nginx-UI backup-restore tampering allows malicious configs to be injected during restore, enabling persistent compromise; nginx-ui is patched in 2.3.4. 📈 **Impact Scope:** Arbitrary command execution on systems where vulnerable Vim is used; persistent configuration changes and service compromise on nginx-ui instances restored from tampered backups; potential for lateral movement and privilege escalation. 🛡️ **Recommended Actions:** - Disable Vim modeline processing (set modeline=0 and modelines=0) and avoid opening untrusted files. - Upgrade nginx-ui to 2.3.4 immediately and verify backup integrity before any restore. 🪢 **Related Resources:** - https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-fhh2-gg7w-gwpq - https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.4 🏷 **Tags:** #Cybersecurity #Vim #nginx-ui

    Post summary

    This advisory announces two new CVEs, provides technical details and mitigations, and urges patching the affected software.

    00000102
    276 followersView on X
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** Vim modeline sandbox bypass allowing arbitrary OS command execution (CVE-2026-34982) 📅 **Timeline:** Disclosure: 2026-04-02, Patch: 2026-03-31 🆔 **CVE-2026-34982** | 📊 CVSS: Not Available (High 🟠) | 📈 EPSS: Not Available% 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** Versions < 9.2.0276 🔧 **Fixed Versions:** 9.2.0276 or later 🫨 **Attack Vectors:** - Local — victim must open a crafted file (user interaction required) 📝 **Summary:** A modeline sandbox bypass in Vim allows specially crafted files to execute arbitrary OS commands as the user opening them. Exploitation requires opening a malicious file but can lead to full user-context compromise, data exposure, and integrity loss. 📈 **Impact Scope:** Arbitrary OS command execution with the privileges of the user running Vim; impacts confidentiality and integrity and can lead to full user-context compromise on affected systems. 🛡️ **Recommended Actions:** - Update Vim to 9.2.0276 or later immediately. - If patching is not possible, disable modelines (add "set nomodeline" to local vimrc). - Run editors with least privilege; avoid running as root/privileged accounts. - Educate users to avoid opening untrusted files and audit deployments via configuration management. 🪢 **Related Resources:** - https://cybersecuritynews.com/vim-modeline-bypass-vulnerability/ - https://github.com/vim/vim/security/advisories/GHSA-8h6p-m6gr-mpw9 🏷 **Tags:** #Cybersecurity #Vim #RCE

    Post summary

    The alert announces CVE-2026-34982, a Vim modeline sandbox bypass that allows arbitrary OS command execution, and details the patch, fixed version, and mitigation actions to protect users.

    0000061
    276 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-34982 Re https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-34982

    Post summary

    Only a basic reference to CVE-2026-34982 is provided via a link, with no further details or actionable intelligence.

    0000069
    4.0K followersView on X
  • VulnTracker@vuln_tracker
    Patch

    @the_yellow_fall Open a file in vim, get owned. CVE-2026-34982 turns the most trusted tool on every Linux server into an attack vector. Modeline sandbox bypass at CVSS 8.2 — and modelines are enabled by default on most distros. Update or add "set nomodeline" to your vimrc. https://vulntracker.io

    Post summary

    The tweet highlights a modeline sandbox bypass in Vim (CVE‑2026‑34982, CVSS 8.2) and urges users to disable modelines or apply a workaround, but it provides no PoC, exploit code, or evidence of current exploitation.

    00000105
    495 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvimvim---

Explore more