CVE-2026-6861: GNU Emacs

High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.

A flaw was found in GNU Emacs. This vulnerability, a memory corruption issue, occurs when Emacs processes specially crafted SVG (Scalable Vector Graphics) CSS (Cascading Style Sheets) data. A local user could exploit this by convincing a victim to open a malicious SVG file, which may lead to a denial of service (DoS) or potentially information disclosure.

Affected products

  • GNU Emacs: from 28.1, up to and including 30.2

Published 2026-04-22. Last modified 2026-06-17.