Code injection vulnerabilities
Code injection covers OS command injection, template injection and similar flaws where attacker input is executed as code by the application. These bugs are easy to weaponize — often a single crafted HTTP request — and are among the fastest classes to move from disclosure to in-the-wild exploitation.
Classification is assigned by the CSIRTS enrichment pipeline from the advisory text. The list below shows the latest advisories tagged code injection, newest first, across national CERTs, vendor PSIRTs and vulnerability databases — exploited marks CVEs in the CISA KEV catalog.
Latest code injection advisories
[UPDATE] [mittel] vim: Mehrere Schwachstellen
[UPDATE] [hoch] IBM License Metric Tool: Mehrere Schwachstellen
[UPDATE] [hoch] Golang Go: Mehrere Schwachstellen
[UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen
[UPDATE] [mittel] Red Hat Ansible Automation Platform (ansible-core): Schwachstelle ermöglicht Codeausführung
[UPDATE] [hoch] NGINX und NGINX Plus: Mehrere Schwachstellen
[UPDATE] [hoch] Dell Secure Connect Gateway: Mehrere Schwachstellen
[UPDATE] [hoch] ffmpeg: Mehrere Schwachstellen
[UPDATE] [hoch] Django: Mehrere Schwachstellen
CVE-2026-18953 - Improper limitation of a pathname in AWS Transform MCP Server
CVE-2026-18420 - Remote Code Execution via Prototype Pollution in OpenSearch Dashboards TSVB Plugin
CVE-2026-83551 - Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK
CVE-2026-18656 & CVE-2026-18657 - Issue with Kiro IDE and CLI - Executable Resolution from Untrusted Project Directory on Windows
CVE-2026-81838 - Zip Slip path traversal in awsdac (diagram-as-code)
CVE-2026-78379 - Consent bypass in Strands Agents Tools python_repl tool
CVE-2026-18733 - Prompt injection bypasses shell tool consent gate in Strands Agents Tools
[UPDATE] [mittel] ffmpeg: Mehrere Schwachstellen
[UPDATE] [mittel] ILIAS: Mehrere Schwachstellen
[UPDATE] [hoch] MISP: Mehrere Schwachstellen
[UPDATE] [hoch] Composer: Mehrere Schwachstellen
[UPDATE] [mittel] Langflow: Mehrere Schwachstellen
[NEU] [kritisch] vm2: Mehrere Schwachstellen ermöglichen Codeausführung
[NEU] [mittel] MongoDB: Mehrere Schwachstellen
[NEU] [hoch] Kibana: Mehrere Schwachstellen
[UPDATE] [mittel] vim (NetBeans): Schwachstelle ermöglicht Codeausführung
[UPDATE] [hoch] Red Hat Enterprise Linux (libsoup): Mehrere Schwachstellen
[UPDATE] [mittel] expat: Schwachstelle ermöglicht Codeausführung
[UPDATE] [mittel] gdk-pixbuf: Schwachstelle ermöglicht Denial of Service und potenzielle Codeausführung
[UPDATE] [mittel] GIMP: Mehrere Schwachstellen ermöglichen Codeausführung
[UPDATE] [hoch] n8n: Mehrere Schwachstellen
[UPDATE] [hoch] Splunk SOAR: Mehrere Schwachstellen
NCSC-2026-0339 [1.00] [M/H] Kwetsbaarheden verholpen in HPE Networking Fabric Composer
IXON VPN Client
[NEW] [high] Drupal Extensions: Multiple Vulnerabilities
[NEW] [medium] Drupal Module: Multiple vulnerabilities
[NEW] [high] Ubuntu Linux (ubuntu-pro-client): Multiple vulnerabilities
[UPDATE] [medium] Red Hat Enterprise Linux (python-wheel): Vulnerability enables privilege escalation and code execution
CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability
Multiples vulnérabilités dans Curl (02 septembre 2026)
USN-8555-2: Ubuntu Advantage Tools (pro client) regression
[UPDATE] [medium] libpng: Multiple vulnerabilities
[NEW] [medium] Keycloak: Multiple vulnerabilities
[UPDATE] [medium] IGEL OS: Vulnerability allows code execution
[UPDATE] [low] vim (.tar and .zip): Multiple Vulnerabilities Enable Code Execution
[NEW] [high] Langflow OSS: Multiple vulnerabilities
[NEW] [high] util-linux: Multiple vulnerabilities
CVE-2026-82078: PaperCut NG/MF Unsafe Reflection Vulnerability
Multiples vulnérabilités dans Microsoft Edge (31 août 2026)
CVE-2026-82078: An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based
Other vulnerability classes
New code injection advisories, in your inbox. The daily briefing covers every advisory in this class the morning after it lands. Subscribe free — one email every morning after 06:00 UTC, one-click unsubscribe. Tracking specific products instead? Watch them from any product page and get alerted only when they ship a new advisory.