[UPDATE] [high] Angular: Multiple Vulnerabilities
An attacker can exploit multiple vulnerabilities in Angular to execute arbitrary code, to conduct a cross-site scripting attack, to disclose information, to bypass security measures, and to conduct a denial of service attack.
CSIRTS triage
- What
- Angular has multiple vulnerabilities enabling arbitrary code execution, cross-site scripting, information disclosure, security bypass, and denial of service.
- Who is affected
- All Angular deployments and applications using affected versions.
- Urgency
- High severity with multiple attack vectors including RCE requires immediate remediation.
- Action
- Upgrade Angular to the patched version addressing CVE-2026-49241, CVE-2026-50178, CVE-2026-54265, CVE-2026-54266, and CVE-2026-54268.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Angular
Get an email when a new Angular advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2038
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-492410.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-501780.50% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-542650.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-542660.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-542680.58% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 46% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-49241 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50178 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-54265 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-54266 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-54268 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMultiple vulnerabilities in IBM products (July 24, 2026)cert-fr-avis
- highGHSA-48r7-hpm6-gfxm: @angular/common: Denial of Service (DoS) via OOM in Date Formatting (formatDate)ghsa
- highGHSA-39pv-4j6c-2g6v: @angular/common: Weak 32-Bit Cache Key Hashing in `HttpTransferCache` Leading to Cross-Re…ghsa
- mediumGHSA-58w9-8g37-x9v5: @angular/compiler: Two-Way Property Binding Sanitization Bypass (XSS)ghsa
Recent advisories for Angular
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[UPDATE] [high] Angular: Multiple Vulnerabilitiescert-bund · 2026-09-01
- high[NEW] [high] Angular: Multiple vulnerabilitiescert-bund · 2026-08-04
- unknownCVE-2026-69151: Angular is a development platform for building mobile and desktop web applications using TypeS…nvd · 2026-08-03
- unknownCVE-2026-69149: Angular is a development platform for building mobile and desktop web applications using TypeS…nvd · 2026-08-03
- unknownCVE-2026-68945: Angular is a development platform for building mobile and desktop web applications using TypeS…nvd · 2026-08-03
- highGHSA-jj27-h5hq-8x99: Angular i18n: Cross-Site Scripting (XSS) via event-handler attributesghsa · 2026-08-03
More from CERT-Bund (BSI) Security Advisories
- medium[NEW] [medium] Langflow: Multiple vulnerabilities2026-09-04
- medium[NEW] [medium] Grafana Enterprise: Multiple vulnerabilities allow gaining user or administrator privileges2026-09-04
- low[NEW] [low] Checkmk: Vulnerability allows Denial of Service2026-09-04
- low[NEW] [low] ImageMagick: Multiple vulnerabilities allow Denial of Service2026-09-04
- critical[NEW] [critical] vm2: Multiple vulnerabilities allow code execution2026-09-04