Red Hat released Vim security updates across RHEL 7 ELS, RHEL 8 and 9 lifecycle channels, and RHEL 10 to remediate command-injection and crafted-file vulnerabilities. CVE-2026-33412 allows arbitrary shell-command execution when an attacker can supply a glob pattern containing a newline on Unix-like systems, subject to Vim's configured shell; upstream fixed it in Vim 9.2.0202. The updates also address CVE-2026-28417, an OS-command-injection issue in the netrw plugin, and CVE-2026-28421, under which a crafted swap file can cause denial of service and disclose information. Several supported channels additionally received fixes for a helpfile-processing arbitrary-code-execution flaw.
Affected organizations should apply the vendor-provided Vim packages through normal Red Hat update procedures. Notable fixed builds include 7.4.629-8.el7_9.1 for RHEL 7 ELS, 8.0.1763-22.el8_10.1 for standard RHEL 8 and 8.10 ELC, 8.2.2637-23.el9_7.2 for RHEL 9, and 9.1.083-6.el10_1.3 for RHEL 10; Red Hat also issued channel-specific updates for older RHEL 8 and RHEL 9 support streams. OpenShift Container Platform 4.13.65 includes updated packages and container images covering Vim and other bundled components, and OCP 4.13 users should upgrade through the applicable release channel.

See real exploitation activity before you spend the cycle.
15 events from the most recent confirmed update back to the earliest known activity.
RHSA-2026:8259 supplied Vim 8.2.2637-23.el9_7.2 for supported RHEL 9 variants and architectures. It fixes the Vim netrw command-injection, crafted-swap-file, and glob() command-injection vulnerabilities.
Red Hat issued RHSA-2026:7711 for supported RHEL 10 deployments, supplying Vim 9.1.083-6.el10_1.3. The update fixes CVE-2026-28417, CVE-2026-28421, and CVE-2026-33412.
RHSA-2026:6915 provided Vim 8.0.1763-22.el8_10.1 for standard RHEL 8 and RHEL 8.10 Extended Life Cycle deployments. It remediates netrw command injection, the crafted-swap-file issue, and CVE-2026-33412 glob() command injection.
Red Hat released RHSA-2026:6736 for RHEL 8.8 Extended Life Cycle Long Life, Telecommunications Update Service, and SAP update offerings. Fixed Vim build 8.0.1763-20.el8_8.1 addresses CVE-2026-33412 and three other Vim flaws.
RHSA-2026:6731 provided Vim 8.0.1763-19.el8_6.5 for supported RHEL 8.6 extended-support repositories. It addressed four Vim vulnerabilities involving helpfile processing, netrw, crafted swap files, and glob().
Red Hat issued RHSA-2026:6729 for RHEL 8.4 AUS and Extended Life Cycle Long Life deployments, supplying Vim 8.0.1763-15.el8_4.1. The advisory remediates four Vim issues including CVE-2026-33412.
RHSA-2026:6730 delivered Vim 8.0.1763-13.el8_2.1 for RHEL Server Advanced Update Support 8.2 on x86_64. It fixed four vulnerabilities, including arbitrary code execution through glob() command injection.
Red Hat released RHSA-2026:6620 for RHEL 9.2 Update Services for SAP Solutions, four-year update, and Extended Life Cycle offerings. It supplies Vim 8.2.2637-20.el9_2.1 to remediate four Vim vulnerabilities including CVE-2026-33412.
RHSA-2026:6619 provided Vim 8.2.2637-16.el9_0.4 for RHEL 9.0 Update Services for SAP Solutions and related supported channels. The update fixes CVE-2026-25749, CVE-2026-28417, CVE-2026-28421, and CVE-2026-33412.
RHSA-2026:6617 supplied Vim 7.4.629-8.el7_9.1 for RHEL 7 ELS on x86_64, s390x, ppc64, and ppc64le. It addresses four Vim issues, including CVE-2026-33412 command injection in glob().
Red Hat issued RHSA-2026:6540 for RHEL 9.4 support channels, providing Vim 8.2.2637-20.el9_4.2. The update remediates the helpfile-processing, netrw command-injection, crafted-swap-file, and glob() command-injection flaws.
Red Hat published RHSA-2026:6539 for RHEL 9.6 Extended Update Support, supplying Vim 8.2.2637-22.el9_6.2 to address CVE-2026-25749, CVE-2026-28417, CVE-2026-28421, and CVE-2026-33412.
Red Hat issued RHSA-2026:6502 for RHEL 10.0 Extended Update Support and specified four-year support offerings, supplying Vim 9.1.083-5.el10_0.2. The update remediates CVE-2026-25749, CVE-2026-28417, CVE-2026-28421, and CVE-2026-33412.
Red Hat released OpenShift Container Platform 4.13.65 with updated packages and container images for the 4.13 stream. The release lists a fix for CVE-2026-33412 along with eight other CVEs affecting bundled components.
Vim versions before 9.2.0202 were vulnerable to arbitrary shell-command execution when an attacker could supply a glob pattern containing a newline on Unix-like systems. Exploitation depends on the user's configured shell; version 9.2.0202 fixes the issue tracked as CVE-2026-33412.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
15 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.