CVE-2026-96269: GNU Emacs
High severity, CVSS 7.5. EPSS: 0.1% chance of exploitation in the next 30 days.
GNU Emacs 28.1 through 31.1 allows arbitrary code execution upon opening a file, because an untrusted value of read-symbol-shorthands affects the intern and unintern functions. This affects the default configuration; no particular user settings are required to trigger it.
Affected products
- GNU Emacs: from 28.1, up to and including 31.1
Published 2026-09-22. Last modified 2026-09-24.