[UPDATE] [high] Angular: Multiple Vulnerabilities
An attacker can exploit multiple vulnerabilities in Angular to gain elevated privileges, execute arbitrary code, bypass security measures, conduct cross-site scripting attacks, create a denial-of-service condition, manipulate or disclose data, redirect users to malicious websites, or hijack sessions.
CSIRTS triage
- What
- Multiple vulnerabilities in Angular enable privilege escalation, code execution, auth bypass, XSS, DoS, data manipulation, phishing, and session hijacking.
- Who is affected
- All Angular deployments running vulnerable versions.
- Urgency
- High — Multiple critical attack vectors including RCE and privilege escalation; remediate urgently.
- Action
- Update Angular to a patched version.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Angular
Get an email when a new Angular advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1930
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-501680.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-501690.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-501700.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-501710.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-501840.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-505550.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-505560.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-505570.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-527250.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-542640.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-50168 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50169 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50170 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50171 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50184 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50555 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50556 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50557 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-52725 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-54264 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-54267 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMultiples vulnérabilités dans les produits IBM (11 septembre 2026)cert-fr-avis
- unknownMultiple vulnerabilities in IBM products (July 24, 2026)cert-fr-avis
- highGHSA-qxh6-94w6-9r5p: @angular/service-worker: Sensitive Header Leakage on Cross-Origin Redirects in Angular Se…ghsa
- mediumGHSA-f3m7-gqxr-g87x: Angular: Template and Attribute Namespace Sanitization Bypass (XSS)ghsa
- highGHSA-hqr9-c56f-3x7f: @angular/platform-server: Improper Neutralization of Input During Web Page Generation ('C…ghsa
- mediumGHSA-95qp-cmmw-mgqv: @angular/service-worker: Request Credential & Cache Policy Strippingghsa
- highGHSA-p3vc-36g9-x9gr: @angular/common: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo)ghsa
- highGHSA-q6f4-qqrg-jv6x: @angular/common: Information Leak via Default Caching of Credentialed Requests in HttpTra…ghsa
- mediumGHSA-692r-grfm-v8x7: @angular/core: Angular Template and Dynamic Component Namespace Bypass leading to Cross-S…ghsa
- mediumGHSA-gv2q-mqqv-365m: Angular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilitiesghsa
- highGHSA-xrxm-cp7j-8xf6: @angular/platform-server: URL Parser Differential leading to SSRF Allowlist Bypassghsa
- highGHSA-rgjc-h3x7-9mwg: Angular Client Hydration DOM Clobbering & Response-Cache Poisoningghsa
Recent advisories for Angular
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[UPDATE] [hoch] Angular: Mehrere Schwachstellencert-bund · 2026-09-14
- high[NEU] [hoch] Angular: Mehrere Schwachstellencert-bund · 2026-09-11
- highGHSA-v3p8-whq6-r5jg: Angular: SSR XSS via Unescaped Content Across DocumentFragment Boundaries in Fallback Raw…ghsa · 2026-09-10
- highGHSA-f6mr-pjwc-34m4: Angular: SSRF and Cross-Origin Credential Disclosure via URL Resolution Discrepancy in SS…ghsa · 2026-09-10
- mediumGHSA-p297-fm68-3q8c: Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaP…ghsa · 2026-09-10
- mediumGHSA-hh8m-fm6v-7cvg: Angular: Sanitization bypass via directive host bindings on concrete host elements in @an…ghsa · 2026-09-10
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service2026-09-15
- high[UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen2026-09-15
- high[UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff2026-09-15
- high[NEU] [hoch] MISP: Mehrere Schwachstellen2026-09-15
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service oder unspezifischer Angri…2026-09-15