https://seclists.org/oss-sec/2026/q2/1048: [vim-security] Arbitrary Code Execution via PHP Omni-Completion in Vim < 9.2.0736
Published Jun 28, 2026
·Updated
Affected Software
1 affected component
vim Vim<9.2.0736
Frequently Asked Questions
1
What is the severity of CVE-2026-XXXX?
The severity of CVE-2026-XXXX is classified as medium.
2
What does CVE-2026-XXXX affect?
CVE-2026-XXXX affects Vim versions prior to 9.2.0736.
3
What type of vulnerability is CVE-2026-XXXX?
CVE-2026-XXXX is an arbitrary code execution vulnerability caused by improper handling of PHP omni-completion.
4
How can I mitigate the risk of CVE-2026-XXXX?
To mitigate the risk of CVE-2026-XXXX, upgrade to Vim version 9.2.0736 or later.
5
What is the impact of CVE-2026-XXXX?
The impact of CVE-2026-XXXX is the potential for arbitrary code execution within the Vim editor.