[UPDATE] [high] Composer: Multiple vulnerabilities allow code execution
An attacker can exploit multiple vulnerabilities in Composer to execute arbitrary program code.
CSIRTS triage
- What
- Multiple vulnerabilities allow arbitrary code execution.
- Who is affected
- Attackers targeting installations of Composer.
- Urgency
- Remediation is high urgency due to the potential for severe impacts.
- Action
- Update to the latest version of Composer.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Composer
Get an email when a new Composer advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1128
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2026-401761.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 61% of all scored CVEs.
- Moderate exploitation riskCVE-2026-402611.7% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 75% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-40176 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-40261 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Composer
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownCVE-2026-11872: The Clever Mega Menu for Visual Composer WordPress plugin through 1.0.1 does not perform a non…nvd · 2026-08-02
- mediumCVE-2026-65568: Contributor Broken Access Control in Visual Composer Website Builder <= 45.15.0 versions.nvd · 2026-07-27
- mediumGHSA-w6w4-rjh9-9r58: c3p0 can, in combination with other libraries, compose to a "sink" for deserialization ga…ghsa · 2026-07-23
- highCVE-2026-65896: Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly val…nvd · 2026-07-23
- mediumGHSA-8mv7-9c27-98vc: Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware(…ghsa · 2026-07-20
- mediumGHSA-gjfg-22fp-rrxx: Composer: Path traversal in package bin field lets dependencies chmod arbitrary host file…ghsa · 2026-07-20
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow Denial of Service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities2026-07-31
- medium[UPDATE] [medium] Linux Kernel (ntfs3): Vulnerability allows information disclosure2026-07-31