CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-47141

criticalcovered by 1 sourcefirst seen 2026-08-06
A remote, anonymous attacker can exploit multiple vulnerabilities in vm2 to execute arbitrary code, bypass security measures, manipulate data, and disclose confidential information.

CSIRTS triage

What
Multiple critical vulnerabilities in vm2 enable unauthenticated remote code execution, security bypass, data manipulation, and information disclosure.
Who is affected
Applications using vm2 for sandboxing or code execution, exposed to untrusted input.
Urgency
Critical severity with code execution capability; immediate patching or mitigation is essential.
Action
Update vm2 to the patched version or replace with a maintained alternative sandbox solution.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-47141

Get an email if CVE-2026-47141 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-47141

CVE.org record

Embed the live status

CVE-2026-47141 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-47141 status](https://www.csirts.com/badge/CVE-2026-47141)](https://www.csirts.com/cve/CVE-2026-47141)