CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-6861

unknowncovered by 1 sourcefirst seen 2026-08-26
Two security issues were discovered in GNU Emacs, which could result in the execution of arbitrary code when opening a malformed file and denial of service when processing malformed PBM/PPM/PGM images. https://security-tracker.debian.org/tracker/DSA-6468-1

CSIRTS triage

What
GNU Emacs contains vulnerabilities allowing arbitrary code execution from malformed files and denial of service from malformed PBM/PPM/PGM images.
Who is affected
Systems running GNU Emacs and processing untrusted files are affected.
Urgency
High urgency; arbitrary code execution is possible when opening crafted files.
Action
Apply Debian security update DSA-6468-1 for GNU Emacs.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-6861

Get an email if CVE-2026-6861 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-6861

CVE.org record

Embed the live status

CVE-2026-6861 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-6861 status](https://www.csirts.com/badge/CVE-2026-6861)](https://www.csirts.com/cve/CVE-2026-6861)