CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-15920

highCVSS 6.1covered by 2 sourcesfirst seen 2026-08-04
An attacker can exploit multiple vulnerabilities in Django to execute arbitrary code, manipulate data, perform cross-site scripting attacks, or trigger a denial of service condition.

CSIRTS triage

What
Multiple vulnerabilities in Django enable arbitrary code execution, data manipulation, cross-site scripting, and denial of service.
Who is affected
Any application running vulnerable Django versions and handling untrusted input is affected.
Urgency
High severity with multiple attack vectors including code execution requires immediate patching regardless of deployment exposure.
Action
Update Django to the latest patched version without delay.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-15920

Get an email if CVE-2026-15920 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-15920

CVE.org record

Embed the live status

CVE-2026-15920 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-15920 status](https://www.csirts.com/badge/CVE-2026-15920)](https://www.csirts.com/cve/CVE-2026-15920)