OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-96442

HIGH · CVSS 7.8 EPSS 0.17% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

A code execution vulnerability in Emacs affects versions prior to 31.2, specifically within the Flymake mode when using language backends other than Lisp. This flaw allows arbitrary code execution from untrusted files during syntax checking, potentially compromising the system with the privileges of the user running Emacs. Users and organizations utilizing Emacs for editing untrusted files should prioritize updating to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-96442
Severity
HIGH
CVSS
7.8
EPSS
0.17%

Original NVD Description

A code execution flaw was found in Emacs, affecting versions prior to 31.2. The Flymake mode using language backends other than Lisp would execute arbitrary code from the edited file while performing syntax checking. Viewing or editing untrusted files using Emacs could lead to arbitrary code execution with the privileges of the user running Emacs.