{"schema_version":1,"title":"Gnu Emacs vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 8 vulnerabilities in Gnu Emacs: 2 in the last 7 days and 8 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-96442, was published on 23 September 2026.","url":"https://junglewise.ai/threats/technologies/emacs","json_url":"https://junglewise.ai/threats/technologies/emacs.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/emacs","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":3,"all_time":8,"critical":0,"exploited":0,"last_7_days":2,"last_30_days":2,"last_90_days":8,"last_365_days":8},"latest":[{"cve":"CVE-2026-96442","cvss":7.8,"epss":0.0017,"slug":"cve-2026-96442-a-code-execution-flaw-was-found-in-emacs-affecting-versions-prior","title":"Emacs Flymake code execution via untrusted files","severity":"high","exploited":false,"published_at":"2026-09-23T11:17:18.55+00:00","url":"https://junglewise.ai/threats/cve-2026-96442-a-code-execution-flaw-was-found-in-emacs-affecting-versions-prior"},{"cve":"CVE-2026-96269","epss":0.0015,"slug":"cve-2026-96269-gnu-emacs-28-1-through-31-1-allows-arbitrary-code-execution-upon","title":"GNU Emacs arbitrary code execution in symbol handling","severity":"info","exploited":false,"published_at":"2026-09-22T21:17:35.15+00:00","url":"https://junglewise.ai/threats/cve-2026-96269-gnu-emacs-28-1-through-31-1-allows-arbitrary-code-execution-upon"},{"cve":"CVE-2026-79992","cvss":7.8,"epss":0.002,"slug":"cve-2026-79992-emacs-tramp-command-injection-via-malicious-filenames","title":"Emacs TRAMP command injection via malicious filenames","severity":"high","exploited":false,"published_at":"2026-08-25T18:18:06.973+00:00","url":"https://junglewise.ai/threats/cve-2026-79992-emacs-tramp-command-injection-via-malicious-filenames"},{"cve":"CVE-2026-77219","cvss":7.1,"epss":0.0019,"slug":"cve-2026-77219-gnu-emacs-integer-overflow-in-pbm-image-loader","title":"GNU Emacs integer overflow in PBM image loader","severity":"high","exploited":false,"published_at":"2026-08-21T21:17:06.59+00:00","url":"https://junglewise.ai/threats/cve-2026-77219-gnu-emacs-integer-overflow-in-pbm-image-loader"},{"cve":"CVE-2026-71394","cvss":6.5,"epss":0.0045,"slug":"cve-2026-71394-gnu-emacs-for-android-improper-validation-in-font-table-parsing","title":"GNU Emacs for Android improper validation in font table parsing","severity":"info","exploited":false,"published_at":"2026-08-10T11:17:28.697+00:00","url":"https://junglewise.ai/threats/cve-2026-71394-gnu-emacs-for-android-improper-validation-in-font-table-parsing"},{"cve":"CVE-2026-71393","cvss":7.5,"epss":0.0067,"slug":"cve-2026-71393-gnu-emacs-integer-overflow-in-sfnt-read-name-table","title":"GNU Emacs integer overflow in sfnt_read_name_table","severity":"info","exploited":false,"published_at":"2026-08-10T11:17:28.56+00:00","url":"https://junglewise.ai/threats/cve-2026-71393-gnu-emacs-integer-overflow-in-sfnt-read-name-table"},{"cve":"CVE-2026-71392","cvss":7.3,"epss":0.0067,"slug":"cve-2026-71392-gnu-emacs-integer-overflow-in-sfnt-read-cmap-format-12","title":"GNU Emacs integer overflow in sfnt_read_cmap_format_12","severity":"info","exploited":false,"published_at":"2026-08-10T11:17:28.397+00:00","url":"https://junglewise.ai/threats/cve-2026-71392-gnu-emacs-integer-overflow-in-sfnt-read-cmap-format-12"},{"cve":"CVE-2026-71391","cvss":0,"epss":0.0054,"slug":"cve-2026-71391-gnu-emacs-off-by-one-error-in-gvar-table-parser","title":"GNU Emacs off-by-one error in gvar table parser","severity":"info","exploited":false,"published_at":"2026-08-10T11:17:28.233+00:00","url":"https://junglewise.ai/threats/cve-2026-71391-gnu-emacs-off-by-one-error-in-gvar-table-parser"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":2}],"related":[{"name":"Gnu Binutils","slug":"binutils","vulnerabilities":36,"url":"https://junglewise.ai/threats/technologies/binutils"},{"name":"Gnu Glibc","slug":"glibc","vulnerabilities":20,"url":"https://junglewise.ai/threats/technologies/glibc"},{"name":"GnuTLS","slug":"gnutls","vulnerabilities":20,"url":"https://junglewise.ai/threats/technologies/gnutls"},{"name":"Gnu LibreDWG","slug":"libredwg","vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/libredwg"},{"name":"GNU tar","slug":"tar","vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/tar"},{"name":"Gnu Bash","slug":"bash","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/bash"},{"name":"GNU C Library","slug":"gnu-c-library","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/gnu-c-library"},{"name":"Gnu Wget","slug":"wget","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/wget"},{"name":"Gnu Grub2","slug":"grub2","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/grub2"},{"name":"GNU Coreutils","slug":"coreutils","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/coreutils"},{"name":"Gnu Cpio","slug":"cpio","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/cpio"},{"name":"Gnu Gawk","slug":"gawk","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/gawk"}],"technology":{"hub":true,"name":"Gnu Emacs","slug":"emacs","vendor":{"name":"Gnu","slug":"gnu","url":"https://junglewise.ai/threats/vendors/gnu"},"aliases":[],"category":"editor","url":"https://junglewise.ai/threats/technologies/emacs"},"most_severe":[{"cve":"CVE-2026-79992","cvss":7.8,"epss":0.002,"slug":"cve-2026-79992-emacs-tramp-command-injection-via-malicious-filenames","title":"Emacs TRAMP command injection via malicious filenames","severity":"high","exploited":false,"published_at":"2026-08-25T18:18:06.973+00:00","url":"https://junglewise.ai/threats/cve-2026-79992-emacs-tramp-command-injection-via-malicious-filenames"},{"cve":"CVE-2026-96442","cvss":7.8,"epss":0.0017,"slug":"cve-2026-96442-a-code-execution-flaw-was-found-in-emacs-affecting-versions-prior","title":"Emacs Flymake code execution via untrusted files","severity":"high","exploited":false,"published_at":"2026-09-23T11:17:18.55+00:00","url":"https://junglewise.ai/threats/cve-2026-96442-a-code-execution-flaw-was-found-in-emacs-affecting-versions-prior"},{"cve":"CVE-2026-77219","cvss":7.1,"epss":0.0019,"slug":"cve-2026-77219-gnu-emacs-integer-overflow-in-pbm-image-loader","title":"GNU Emacs integer overflow in PBM image loader","severity":"high","exploited":false,"published_at":"2026-08-21T21:17:06.59+00:00","url":"https://junglewise.ai/threats/cve-2026-77219-gnu-emacs-integer-overflow-in-pbm-image-loader"},{"cve":"CVE-2026-71393","cvss":7.5,"epss":0.0067,"slug":"cve-2026-71393-gnu-emacs-integer-overflow-in-sfnt-read-name-table","title":"GNU Emacs integer overflow in sfnt_read_name_table","severity":"info","exploited":false,"published_at":"2026-08-10T11:17:28.56+00:00","url":"https://junglewise.ai/threats/cve-2026-71393-gnu-emacs-integer-overflow-in-sfnt-read-name-table"},{"cve":"CVE-2026-71392","cvss":7.3,"epss":0.0067,"slug":"cve-2026-71392-gnu-emacs-integer-overflow-in-sfnt-read-cmap-format-12","title":"GNU Emacs integer overflow in sfnt_read_cmap_format_12","severity":"info","exploited":false,"published_at":"2026-08-10T11:17:28.397+00:00","url":"https://junglewise.ai/threats/cve-2026-71392-gnu-emacs-integer-overflow-in-sfnt-read-cmap-format-12"},{"cve":"CVE-2026-71394","cvss":6.5,"epss":0.0045,"slug":"cve-2026-71394-gnu-emacs-for-android-improper-validation-in-font-table-parsing","title":"GNU Emacs for Android improper validation in font table parsing","severity":"info","exploited":false,"published_at":"2026-08-10T11:17:28.697+00:00","url":"https://junglewise.ai/threats/cve-2026-71394-gnu-emacs-for-android-improper-validation-in-font-table-parsing"},{"cve":"CVE-2026-71391","cvss":0,"epss":0.0054,"slug":"cve-2026-71391-gnu-emacs-off-by-one-error-in-gvar-table-parser","title":"GNU Emacs off-by-one error in gvar table parser","severity":"info","exploited":false,"published_at":"2026-08-10T11:17:28.233+00:00","url":"https://junglewise.ai/threats/cve-2026-71391-gnu-emacs-off-by-one-error-in-gvar-table-parser"},{"cve":"CVE-2026-96269","epss":0.0015,"slug":"cve-2026-96269-gnu-emacs-28-1-through-31-1-allows-arbitrary-code-execution-upon","title":"GNU Emacs arbitrary code execution in symbol handling","severity":"info","exploited":false,"published_at":"2026-09-22T21:17:35.15+00:00","url":"https://junglewise.ai/threats/cve-2026-96269-gnu-emacs-28-1-through-31-1-allows-arbitrary-code-execution-upon"}],"generated_at":"2026-09-26T12:07:00.15149+00:00"}