Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4304 articles · 221513 vulns · 37/41 feeds (7d)
← Back to list
7.8
CVE-2026-96442EXPLOITED
red hat · red hat enterprise linux

Emacs: emacs: arbitrary code execution, incomplete fix for cve-2024-53920

Description

A code execution flaw was found in Emacs, affecting versions prior to 31.2. The Flymake mode using language backends other than Lisp would execute arbitrary code from the edited file while performing syntax checking. Viewing or editing untrusted files using Emacs could lead to arbitrary code execution with the privileges of the user running Emacs.

Affected Products

VendorProductVersions
red hatred hat enterprise linux—

References

  • https://access.redhat.com/security/cve/CVE-2026-96442(vdb-entry, x_refsource_REDHAT)
  • https://bugzilla.redhat.com/show_bug.cgi?id=2537347(issue-tracking, x_refsource_REDHAT)
  • https://github.com/emacs-mirror/emacs/commit/135e6f63f08fee3d374fa1a5187bce941a2d3e3c
  • https://github.com/emacs-mirror/emacs/commit/abc802ee2eb0b1663349ddf22a461f8e54a383fb
  • https://www.openwall.com/lists/oss-security/2026/09/14/1

Related News (1 articles)

Tier C
VulDB4h ago
CVE-2026-96442 | Red Hat Emacs up to 31.1 Flymake mode code injection
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.17.8 NONE
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-94
PublishedSep 23, 2026
Last enriched3h ago
Tags
remote code executionfile manipulationdenial of servicemultiple vulnerabilities
Trending Score46
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-94184EXP
Fetchmail: fetchmail: stack-based buffer overflow in ntlm authentication (fetchmail-sa-2026-01)
Trending: 56
NONECVE-2026-87766EXP
Bubblewrap: bubblewrap: symlink traversal via /oldroot allows writing files outside sandbox during setup
Trending: 52
NONECVE-2026-93676EXP
Xdg-dbus-proxy: xdg-dbus-proxy: filtering for broadcast messages bypasses path/interface/member checks
Trending: 47
NONECVE-2026-95511
Cups: cups-filters: cups-filters: lpadmin can escalate to root via privileged serial backend (cups2root)
Trending: 40
NONECVE-2026-93558
Io.netty/netty-codec-http: netty: unbounded per-connection queue growth in websocketserverextensionhandler leads to denial of service
Trending: 37

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 23, 2026
Discovered by ZDM
Sep 23, 2026
Actively Exploited
Sep 23, 2026
Exploit Available
Sep 23, 2026