CVE-2026-79079

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/gtk/menu_popup.c components

Published 2026-09-21. Last modified 2026-09-22.