CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-42170

highCVSS 7.8covered by 2 sourcesfirst seen 2026-08-08
A remote, anonymous attacker can exploit a vulnerability in GIMP to execute arbitrary code.

CSIRTS triage

What
A remote attacker can execute arbitrary code in GIMP.
Who is affected
All users running GIMP are affected.
Urgency
High severity and unpatched status warrant immediate attention despite no active exploitation reported.
Action
Monitor for patch availability and apply immediately upon release; restrict GIMP usage in high-risk environments until patched.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-42170

Get an email if CVE-2026-42170 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-42170

CVE.org record

Embed the live status

CVE-2026-42170 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-42170 status](https://www.csirts.com/badge/CVE-2026-42170)](https://www.csirts.com/cve/CVE-2026-42170)