CVE-2026-96269: GNU Emacs 28.1 through 31.1 allows arbitrary code execution upon opening a file, because an untrusted value of read-symbol-shorthands affects the intern and unintern functions. This affects the default configuration; no particular user settings are required to trigger it.

Overview

Severity
N/A
Exploit Status
Not Exploited
Patch Tuesday
2026-Sep
Released
2026-09-24
EPSS Score
0.18% (percentile: 8.2%)

Affected Products (1)

Other

  • 21861-17084

Revision History

  • 2026-09-24: Information published.